CVE-2010-0094
published 2010-04-01CVE-2010-0094: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote…
PriorityP183high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
81.59%
99.6th percentile
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit delivers a malicious JAR (Applet.jar) via HTTP containing exploit class files (Exploit.class, Exploit$1.class, Exploit$1$1.class, Exploit$2.class, Payloader.class, PayloadClassLoader.class) and a serialized payload (payload.ser). Detect HTTP responses serving a JAR with these specific class file names. ↗
- →The vulnerability is triggered via deserialization of RMIConnectionImpl objects. Monitor Java processes for unexpected ClassLoader instantiation or privilege escalation during RMI deserialization. ↗
- →Deserialization of the RMIConnectionImpl class resulted in more permissions than required being assigned to the unwrapped object. This could be misused to bypass access restrictions. Alert on unexpected permission grants during Java RMI deserialization events. ↗
- ·The vulnerability affects Java SE 6 prior to Update 19 and Java SE 5.0 prior to Update 23. The Metasploit module targets these specific version ranges. ↗
- ·The NVD advisory references Java SE and Java for Business 6 Update 18 and 5.0 Update 23 as the affected versions, meaning detections should focus on environments running these or earlier versions. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
vendor_vmware·2011-02-10·CVSS 5.0
CVE-2008-0085 [MEDIUM] Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
VMSA-2011-0003: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory Issue date: VMware Security Advisory Updated on: VMware Security Advisory CVE numbers:
CVEs: CVE-2008-0085, CVE-2008-0086, CVE-2008-0106, CVE-2008-0107, CVE-2008-3825, CVE-2008-5416, CVE-2009-1384, CVE-2009-2693, CVE-2009-2901, CVE-2009-2902, CVE-2009-3548, CVE-2009-3555, CVE-2009-4308, CVE-2010-0003, CVE-2010-0007, CVE-2010-0008, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085,
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2010-04-07·CVSS 5.8
CVE-2009-3555 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3
protocols. If an attacker could perform a machine-in-the-middle attack at the
start of a TLS connection, the attacker could inject arbitrary content
at the beginning of the user's session. (CVE-2009-3555)
It was discovered that Loader-constraint table, Policy/PolicyFile,
Inflater/Deflater, drag/drop access, and deserialization did not correctly
handle certain sensitive objects. If a user were tricked into running a
specially crafted applet, private information could be leaked to a remote
attacker, leading to a loss of privacy. (CVE-2010-0082, CVE-2010-0084,
CVE-2010-0085, CVE-2010-0088, CVE-2010-0091, CVE-2010-0094)
It was discovered that AtomicReferenceAr
Red Hat
OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947)
vendor_redhat·2010-03-30·CVSS 7.5
CVE-2010-0094 [HIGH] OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947)
OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
GHSA
GHSA-6pp2-r37j-3rhq: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5
ghsa_unreviewed·2022-05-02
CVE-2010-0094 [HIGH] GHSA-6pp2-r37j-3rhq: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
VulnCheck
Oracle Java Runtime Environment (JRE) RMIConnectionImpl Objects Vulnerability
vulncheck·2010·CVSS 7.5
CVE-2010-0094 [HIGH] Oracle Java Runtime Environment (JRE) RMIConnectionImpl Objects Vulnerability
Oracle Java Runtime Environment (JRE) RMIConnectionImpl Objects Vulnerability
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
Affected: sun jre
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the pr
No detection rules found.
Exploit-DB
Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
exploitdb·2010-09-27
CVE-2010-0094 Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
---
##
# $Id: java_rmi_connection_impl.rb 10490 2010-09-27 00:09:17Z egypt $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
require 'rex'
class Metasploit3 false })
def initialize( info = {} )
super( update_info( info,
'Name' => 'Java RMIConnectionImpl Deserialization Privilege Escalation Exploit',
'Description' => %q{
This module exploits a vulnerability in the Java Runtime Environment
that allows to deserialize a MarshalledObject containing a custom
classloader under a privileged
Metasploit
Java RMIConnectionImpl Deserialization Privilege Escalation
metasploit
Java RMIConnectionImpl Deserialization Privilege Escalation
Java RMIConnectionImpl Deserialization Privilege Escalation
This module exploits a vulnerability in the Java Runtime Environment that allows to deserialize a MarshalledObject containing a custom classloader under a privileged context. The vulnerability affects version 6 prior to update 19 and version 5 prior to update 23.
Bugzilla
CVE-2010-0094 OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947)
bugzilla·2010-03-22·CVSS 7.5
CVE-2010-0094 [HIGH] CVE-2010-0094 OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947)
CVE-2010-0094 OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947)
Deserialization of the RMIConnectionImpl class resulted in more permissions than required being assigned to the unwrapped object. This could be misused to bypass access restrictions.
Discussion:
This is now public:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0339 https://rhn.redhat.com/errata/RHSA-2010-0339.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0337 https://rhn.redhat.com/errata/RHSA-2010-0337.html
---
This issue has been addressed in
Bugzilla
CVE-2010-0417 HelixPlayer / RealPlayer: rule book handling heap corruption
bugzilla·2010-02-04·CVSS 5.0
CVE-2010-0417 [MEDIUM] CVE-2010-0417 HelixPlayer / RealPlayer: rule book handling heap corruption
CVE-2010-0417 HelixPlayer / RealPlayer: rule book handling heap corruption
An insufficient array boundary checking flaw was fixed in Real Player's / HelixPlayer's RuleBook structures handling code, leading to a heap corruption:
http://lists.helixcommunity.org/pipermail/common-cvs/2008-January/015484.html
https://helixcommunity.org/viewcvs/common/util/rlstate.cpp?view=log#rev1.10
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2010:0094 https://rhn.redhat.com/errata/RHSA-2010-0094.html
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
- Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
1. Was our software used outside of its intended functionality to pull classified information from a person’s c
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
Was our software used outside of its intended functionality to pull classified information from a person’s comput
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.apple.com/archives/security-announce/2010//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://marc.info/?l=bugtraq&m=127557596201693&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39292http://secunia.com/advisories/39317http://secunia.com/advisories/39659http://secunia.com/advisories/39819http://secunia.com/advisories/40545http://secunia.com/advisories/43308http://support.apple.com/kb/HT4170http://support.apple.com/kb/HT4171http://ubuntu.com/usn/usn-923-1http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0337.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0338.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0339.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0383.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0471.htmlhttp://www.securityfocus.com/archive/1/510527/100/0/threadedhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2010/1191http://www.vupen.com/english/advisories/2010/1454http://www.vupen.com/english/advisories/2010/1793http://www.zerodayinitiative.com/advisories/ZDI-10-051https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10851https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14351http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.apple.com/archives/security-announce/2010//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://marc.info/?l=bugtraq&m=127557596201693&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39292http://secunia.com/advisories/39317http://secunia.com/advisories/39659http://secunia.com/advisories/39819http://secunia.com/advisories/40545http://secunia.com/advisories/43308http://support.apple.com/kb/HT4170http://support.apple.com/kb/HT4171http://ubuntu.com/usn/usn-923-1http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0337.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0338.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0339.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0383.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0471.htmlhttp://www.securityfocus.com/archive/1/510527/100/0/threadedhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2010/1191http://www.vupen.com/english/advisories/2010/1454http://www.vupen.com/english/advisories/2010/1793http://www.zerodayinitiative.com/advisories/ZDI-10-051https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10851https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14351
2010-04-01
Published
Exploited in the wild