
Update - 08/28/2012
Dell SonicWALL UTM Research team discovered spam campaigns involving Blackhole exploit kit URLs already utilizing the new Java Zero Day exploit that we analyzed yesterday.
A sample e-mail message from the Intuit Spam campaign:
Structure of the exploit file that gets executed on the victim machine if the user clicks on the URL:
The malicious executable contacts.exe that gets downloaded on the target machine as a result of a successful exploit run in this case is a Cridex banking Trojan variant
Original Alert: Published - 08/27/2012
Dell SonicWALL UTM Research team found reports of a new zero-day vulnerability in the wild targeting Java that allows an attacker to download and execute a malicious executable on the victim machine.
We were able to confirm this exploit on the latest version 7 of Java in our research lab:
java version "1.7.0_06"
Java(TM) SE Runtime Environment (build 1.7.0_06-b24)
It is interesting to note that this exploit does not work on Java version 6. There is no information available on Oracle's security advisory page at the time of writing this alert about this issue.
Infection Cycle
Dell SonicWALL Gateway AntiVirus provides protection against this threat via following signatures:
Share This Article

An Article By
An Article By
Security News
Security News