Java 7 Update 21 - Applet Security Change Analysis
ID: 585bb815-34a9-5ebd-b1cc-fbe1250ef116
STIX ID: report--585bb815-34a9-5ebd-b1cc-fbe1250ef116
Feed Name: TrustedSec blog
Threat Score
Oracle's Java 7 update 21 introduced UI changes that flag untrusted applets, but the underlying applet framework still permits full code execution once a user runs an applet; TrustedSec's testing using the Social-Engineer Toolkit shows the repeater behavior can still present shells and penetration-test success rates remained ~87% for self-signed applets, demonstrating that the visual warnings do not mitigate the practical risk of applet-based code execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
