YAJ0 - Yet Another Java Zero Day Exploit

ImAMacGuy
Valued Contributor II

http://blog.fireeye.com/research/2013/02/yaj0-yet-another-java-zero-day-2.html

detected a brand new Java zero-day vulnerability that was used to attack multiple customers. Specifically, we observed successful exploitation against browsers that have Java v1.6 Update 41 and Java v1.7 Update 15 installed.

6 REPLIES 6

mm2270
Legendary Contributor III

sigh

nkalister
Valued Contributor

mm2270
Legendary Contributor III

They're probably not willing to incur that backlash again after the last time they jumped the gun on the blacklisting.

donmontalvo
Esteemed Contributor III

LOLOL...

RT "@hammen: After the last month, earned 2 more IT certs: "Certified Flash Update Deployment" (CFUD) and "Certified Java Update Deployment" (CJUD)"

--
https://donmontalvo.com

mm2270
Legendary Contributor III

@donmontalvo-
Hahaha! I seriously need to put that onto my resume. I think we all should. Never know, it could prove handy in our next gigs! :D

Chris_Hafner
Valued Contributor II

If only we could leverage xprotect!

EDIT: discussed and answered in
https://jamfnation.jamfsoftware.com/discussion.html?id=6696