Rapid7 Vulnerability & Exploit Database

QuickTime: unspecified vulnerability allows arbitrary code execution via malicious Java applets (CVE-2007-3751)

Back to Search

QuickTime: unspecified vulnerability allows arbitrary code execution via malicious Java applets (CVE-2007-3751)

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
11/07/2007
Created
07/25/2018
Added
10/25/2010
Modified
10/03/2016

Description

Multiple vulnerabilities exist in QuickTime for Java, which may allow untrusted Java applets to obtain elevated privileges. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker may cause the disclosure of sensitive information and arbitrary code execution with elevated privileges. This update addresses the issues by making QuickTime for Java no longer accessible to untrusted Java applets. Credit to Adam Gowdiak for reporting this issue.

Solution(s)

  • quicktime-upgrade-7_3_0

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;