Flaw found in MS Java Virtual Machine

NEWS A German researcher at the University of Marburg has uncovered a security flaw in Microsoft's Java Virtual Machine (JVM). The flaw is a bug in Microsoft's bytecode verifier. According to Princeton University's Secure Internet Programming (SIP) unit, the bug allows for the creation of a malicious applet that can modify and delete files or eavesdrop on the user's activities. The explanation by Princeton's SIP team is on their site: "As of October 11, 1999, all recent versions of Microsoft's JVM for Windows appear to be vulnerable, so users of recent versions of Internet Explorer are affected by this flaw. A malicious applet could also be embedded in an e-mail message read using Microsoft Outlook." Microsoft has posted a new version of its JVM that it claims will eliminates the flaw at http://www.microsoft.com/java .

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters