Six ways to protect against the new actively exploited Java vulnerability

28.08.2012

Instructions on how to do the latter for the most popular Web browsers are detailed in published by the United States Computer Emergency Readiness Team (US-CERT) on Monday.

This is probably the most effective method of mitigating the risks associated with the Java new vulnerability or similar ones that might be discovered in the future.

However, it has the drawback of not being practical in some environments, especially business ones where Java-based Web applications are necessary for important operations.

"Most consumers never need Java, but many corporate users require it for things like GoTo Meeting and WebEx," Chester Wisniewski, senior security adviser at antivirus vendor Sophos, said Tuesday via email. "In a corporate environment you may be able to control JavaW.exe and make sure it will only execute certain applets or contact known good IP ranges for services you use that require Java."

Another solution was proposed by Wolfgang Kandek, the chief technology officer at security vendor Qualys, and consists of using the Zone-based security mechanism of Internet Explorer to in order to restrict which websites that can load Java applets.