Exploit:Java/CVE-2013-0422 - advice please

Soldato
Joined
27 Dec 2009
Posts
11,104
A few days ago my virus scan picked up some Java Exploits so I did a full virus scan and removed them, updated Java and did a full Malwarbytes scan which didn't find anything.

Did another scan yesterday which was clear.

Today it came up with Exploit:Java/CVE-2013-0422.

I have to admit to using both Internet Explorer and Firefox. As far as I'm aware I've only been to legit websites recently (a dangerous assumption I know) and I'm trying to work out where this is coming from and how serious a problem it is. Had a look in Firefox Plugins (for the first time!) and found a warning next to Java Deployment Toolkit that it is "known to be vulnerable" so I've set it to "never activate". The only Extension I have is Download Helper, which I understand to be legit.

Have also now set Java security to very high in the Control Panel. Anything else I should be doing - apart from nuking it from orbit?
 
Why do you need Java?
Are you using the latest version of Java? Java 7 Update 45

Disabling the web plug-in is the best option. http://www.java.com/en/download/help/disable_browser.xml

Yes I updated to the latest version of Java before I got the second exploit. Have put all the security settings to 11, however some things now don't seem to work e.g. media and comment features on the BBC website and adding smilies to posts here...
 
Pretty sure those sites don't require Java at all... especially this site. I would just uninstall it unless you have a very good reason to keep it installed.
 
This is getting weird. Yesterday I changed the Java security setting and "unticked" enable in browser, ran security scans, all clear. Just ran a virus scan and it found Exploit:Java/CVE-2012-4681

How is this even possible? I think I will go for uninstalling Java.
 
Yes I updated to the latest version of Java before I got the second exploit. Have put all the security settings to 11, however some things now don't seem to work e.g. media and comment features on the BBC website and adding smilies to posts here...

This is getting weird. Yesterday I changed the Java security setting and "unticked" enable in browser, ran security scans, all clear. Just ran a virus scan and it found Exploit:Java/CVE-2012-4681

How is this even possible? I think I will go for uninstalling Java.

Don't confuse Java with Javascript.

Please post the log file.
 
Back
Top Bottom