• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Java

CVE-2018-3211: Java Usage Tracker Local Elevation of Privilege on Windows

  • Posted on:October 17, 2018 at 5:59 am
  • Posted in:Exploits, Vulnerabilities
  • Author:
    William Gamazo Sanchez (Vulnerability Research)
0

We found design flaw/weakness in Java Usage Tracker that can enable hackers to create arbitrary files, inject attacker-specified parameters, and elevate local privileges. In turn, these can be chained and used to escalate privileges in order to access resources in affected systems that are normally protected or restricted to other applications or users.

We’ve worked with Oracle through our Zero Day Initiative to patch this flaw, and this has been fixed via Oracle’s October patch update. Users and businesses are accordingly urged to patch and update their version of Java.

In this blog post, we will delve into how this flaw works on Windows — how Java Usage Tracker works and defining the conditions that enabled the exploit.

Read More
Tags: CVE-2018-3211JavaJava Usage Tracker

Why Vulnerability Research Is A Good Thing

  • Posted on:August 14, 2015 at 1:22 am
  • Posted in:Targeted Attacks, Vulnerabilities
  • Author:Raimund Genes (Chief Technology Officer)
1

Earlier this week Oracle’s CSO released a blog post that talked about why people should stop looking for vulnerabilities in their software products. Needless to say, this did not go down well with the security community – and the post was soon taken down with a statement from the company adding that the post “does not reflect our…

Read More
Tags: ExploitJavaOraclevulnerability

OS X Zero-days on the Rise—A 2015 Midyear Review and Outlook on Advanced Attack Surfaces

  • Posted on:August 12, 2015 at 8:36 am
  • Posted in:Exploits, Targeted Attacks, Vulnerabilities
  • Author:
    Weimin Wu (Threat Analyst)
0

2015 has so far been a very busy year for security researchers. The data leaked from Hacking Team shocked many, thanks to the multiple zero-days that were disclosed, as well as emails discussing the unscrupulous trade in exploits and “tools”. Cybercriminals (including exploit kit authors) have been hard at work integrating these newly-discovered flaws into their “products”…

Read More
Tags: 0dayandroidExploitsFlashInternet ExplorerJavaOSXvulnerabilityWindowszero day

Analyzing the Pawn Storm Java Zero-Day – Old Techniques Reused

  • Posted on:July 17, 2015 at 7:03 am
  • Posted in:Exploits, Targeted Attacks, Vulnerabilities
  • Author:
    Jack Tang (Threats Analyst)
0

Java used to be a favored vulnerability target for cybercriminals. However, in recent years that has not been the case. The now-fixed Java zero-day that was used in the Pawn Storm campaign was, in fact, the first time in nearly two years that a zero-day had been found and reported in Java. This can be attributed, in part,…

Read More
Tags: 0dayExploitJavaPawn Stormvulnerability

Cross-Signed Certificates Crash Android

  • Posted on:December 11, 2014 at 11:00 pm
  • Posted in:Mobile, Vulnerabilities
  • Author:
    Wish Wu (Mobile Threat Response Engineer)
2

We have discovered a vulnerability in Android that affects how cross-signed certificates are handled. No current Android release correctly handles these certificates, which are created when two certificates are signed with a looped certificate chain (certificate A signs certificate B; certificate B signs certificate A). We’ve already notified Google about this vulnerability, and there is no fix…

Read More
Tags: androidbugscertificatesJavaMobilevulnerability
Page 1 of 412 › »

Security Predictions for 2020

  • Cybersecurity in 2020 will be viewed through many lenses — from differing attacker motivations and cybercriminal arsenal to technological developments and global threat intelligence — only so defenders can keep up with the broad range of threats.
    Read our security predictions for 2020.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Popular Posts

Sorry. No data so far.

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.