New
#1
Serious New Java Flaw Affects All Versions of Windows
read here.....Serious New Java Flaw Affects All Current Versions of Windows | threatpost
There is a serious vulnerability in Java that leaves users running any of the current versions of Windows open to simple Web-based attacks that could lead to a complete compromise of the affected system. Two separate researchers released information on the vulnerability on Friday, saying that it has been present in Java for years.
The problem lies in the Java Web Start framework, a technology that Sun Microsystems developed to enable the simplified deployment of Java applications. In essence, the JavaWS technology fails to validate parameters passed to it from the command line, and attackers can control those parameters using specific HTML tags on a Web page, researcher Ruben Santamarta said in an advisory posted Friday morning.In short, if you have a recent version of Java running on a Windows machine, you're affected by this flaw.The workaround for this problem is to disable JavaWS and Javaws.exe, Santamarta said in his advisory