← back
CVE-2010-1423

CVE-2010-1423

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 56%
from disclosure to weapon0 days
Published on NVDApr 15
1st PoCApr 9
metasploitApr 9
exploitation probability
56%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.