Security Advisory

CVE-2009-1672

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-05-18 18:00:00
Last updated 2024-08-07 05:20:35
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.