Detail
This module takes advantage of the default configuration of the RMI Registry and RMI Activation services, which allow loading classes from any remote (HTTP) URL. As it invokes a method in the RMI Distributed Garbage Collector which is available via every RMI endpoint, it can be used against both rmiregistry and rmid, and against most other (custom) RMI endpoints as well.
Solution Advice
Change the default configuration of RMI Registry and RMI Activation services.
See the following links for specific information:
- https://github.com/rapid7/metasploit-framework/pull/4203
- https://github.com/rapid7/metasploit-framework/issues/6445
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →