Remote File Access Vulnerability in Microsoft Java Implementation for Internet Explorer
CVE-2002-1291

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
29 November 2002

Summary

The vulnerability in the Microsoft Java implementation, utilized by Internet Explorer, allows remote attackers to exploit a weakness in the applet tag. By setting a codebase to a specific 'file://%00' URL containing a null character, attackers can gain unauthorized access to arbitrary local files and network shares. This poses a significant risk as it enables the potential exposure of sensitive data without proper authentication or user consent.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.