Dissecting The CVE-2013-2460 Java Exploit
ID: b38a66f7-1f7e-5b8c-b0d1-adf2fb71df70
STIX ID: report--b38a66f7-1f7e-5b8c-b0d1-adf2fb71df70
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive summary:** This report documents a Java sandbox bypass via the vulnerable sun.tracing.ProviderSkeleton.invoke implementation: exploit code uses Class.forName and MethodHandles.Lookup to load internal Rhino classes, define a malicious ClassLoader, and set the SecurityManager to null, enabling privileged actions; the write-up includes a Flashpack exploit-kit sample, Java/JavaScript deobfuscation steps, and a YARA signature for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
