Description
This module exploits a flaw within the handling of MixerSequencer objects in Java 6u18 and before.
Exploitation id done by supplying a specially crafted MIDI file within an RMF File. When the MixerSequencer objects is used to play the file, the GM_Song structure is populated with a function pointer provided by a SONG block in the RMF. A Midi block that contains a MIDI with a specially crafted controller event is used to trigger the vulnerability.
When triggering the vulnerability "ebx" points to a fake event in the MIDI file which stores the shellcode. A "jmp ebx" from msvcr71.dll is used to make the exploit reliable over java updates.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/browser/java_mixer_sequencermsf undefined(java_mixer_sequencer) > show actions ...actions...msf undefined(java_mixer_sequencer) > set ACTION < action-name >msf undefined(java_mixer_sequencer) > show options ...show and set options...msf undefined(java_mixer_sequencer) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub