
Dell SonicWALL threat team has observed live malware exploiting CVE-2013-2465 in the wild. The vulnerability referred by CVE-2013-2465 is related to Incorrect image channel verification in Java Runtime Environment (JRE)'s 2D component in Oracle Java SE, and the vulnerable versions include Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7. By exploiting the issue, an attacker can inject and execute arbitrary code remotely.
By exploiting this vulnerability, the observed malware executes the following steps:
a. Create a "mspaints.exe" file with the following codes:
b. Execute mspaints.exe
c. mspaints copies itself in system directory and deletes the first copy
d. connects to malicious webpage:
Dell SonicWALL has created the following IPS signatures to prevent attacks addressing this vulnerability:
Share This Article

An Article By
An Article By
Security News
Security News