Description
This module abuses the JMX classes from a Java Applet to run arbitrary Java code outside of the sandbox as exploited in the wild in February of 2013. Additionally, this module bypasses default security settings introduced in Java 7 Update 10 to run unsigned applet without displaying any warning to the user.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/browser/java_jre17_jmxbean_2msf undefined(java_jre17_jmxbean_2) > show actions ...actions...msf undefined(java_jre17_jmxbean_2) > set ACTION < action-name >msf undefined(java_jre17_jmxbean_2) > show options ...show and set options...msf undefined(java_jre17_jmxbean_2) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub