|
Oracle Java SE contains a flaw that that is due to the JavaFX Jar file being signed by the program and installed to a users system without interaction. This may allow an attacker to invoke an arbitrary argument and trusted call stack within the main method of any trusted class, which in-turn will allow the attacker to execute arbitrary code.
|