Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-7025744

privilege escalation in jusched.exe,jucheck.exe by clicking "More Information"

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Not an Issue
    • Icon: P3 P3
    • None
    • 6u24
    • install
    • x86
    • windows_7

      FULL PRODUCT VERSION :


      ADDITIONAL OS VERSION INFORMATION :
      Microsoft Windows [Version 6.1.7601]

      A DESCRIPTION OF THE PROBLEM :
      The jusched task runs as the local user, but the jucheck task runs as an Administrator, perhaps the administrative user who installed the application originally.

      When an update is available for Java, and clicking the taskbar icon indicating a "Java Update Available", I am presented with a dialog to install the update. In this dialog there is a "More information" link which launches IE. This instance of IE is started as an Administrator. From there you can utilize the various features of IE to gain Administrative access.


      REPRODUCIBILITY :
      This bug can be reproduced often.

            Unassigned Unassigned
            webbuggrp Webbug Group
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: