It's absolutely a bug in the JRE that it's executable format is a) completely unsigned and b) allows crap at the start of it.
If there's a bug in Windows here, there's a bug in the JRE.
If there's a bug in Windows here, there's a bug in the JRE.
Are there any comparable virtual machines that require signed bytecode by default? I’ve personally never heard of it, most of the time it’s verified when the package is downloaded, rather than when it’s executed.
Windows is basically completely responsible for this: Windows validates the MSI, windows knows what an MSI is, Windows knows it will be run by the JRE and validates it just as an MSI instead.