Bypassing StandardSecurityManager Restrictions in Microsoft Java Virtual Machine

Bypassing StandardSecurityManager Restrictions in Microsoft Java Virtual Machine

CVE-2002-1292 · HIGH Severity


The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class ( and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.

Learn more about our Web Application Penetration Testing UK.