cbcvebase.
CVE-2009-3869
published 2009-11-05

CVE-2009-3869: Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0…

PriorityP273critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
65.46%
99.2th percentile
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.

Affected

136 ranges· showing 25
VendorProductVersion rangeFixed in
oraclebea_product_suite
sunjdk
sunjdk
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

pathdata/exploits/CVE-2009-3869.jar
  • Exploit delivers a malicious JAR file via HTTP; detect HTTP responses serving a .jar file with Content-Type 'application/octet-stream' and 'Pragma: no-cache' headers from a browser-facing server, especially when preceded by an HTML page containing serialized payload data in PARAM tags.
  • The exploit HTML page passes a serialized native payload to the applet via PARAM tags; inspect applet HTML for PARAM tags containing hex-encoded shellcode blobs.
  • The Metasploit module uses a randomly named JAR (32 random alphanumeric chars + '.jar') served from the exploit URI; detect requests for randomly named .jar files from Java user-agents in browser traffic.
  • The exploit targets Sun JRE versions 1.6.0_u11 and 1.6.0_u16 on Windows XP SP3; alert on Java plugin User-Agent strings indicating these specific versions in combination with JAR download activity.
  • The exploit module is located at multi/browser/java_setdifficm_bof; Metasploit handler traffic can be identified by the module's URI pattern and the redirect behavior (server redirects to base path ending with '/').
  • ·The Metasploit module payload space is limited to 1024 bytes and BadChars is empty; native payloads only — Java/interpreted payloads will not work with this exploit.
  • ·Automatic target detection is disabled in the module; the operator must manually select the target platform (Windows x86, Mac OS X PPC, or Mac OS X x86).
  • ·Vulnerable versions span multiple JRE/JDK branches: JDK and JRE 6 Update 16 and earlier, JDK and JRE 5.0 Update 21 and earlier, SDK and JRE 1.4.2_23 and earlier, and SDK and JRE 1.3.1_26 and earlier.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.