CVE-2010-0886
published 2010-04-20CVE-2010-0886: Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote…
PriorityP182critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
69.95%
99.3th percentile
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jre | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploit delivery via OBJECT tag with Java Deployment Toolkit CLSID or MIME type invoking .launch() with argument-injected URLs containing -J, -XXaltjvm, or -jar flags ↗
- →Monitor for javaws.exe process launches with command-line arguments containing -J-XXaltjvm= pointing to UNC paths (\\<IP>\<share>), indicating attempted DLL hijack via WebDAV ↗
- →Detect WebDAV PROPFIND requests for .dll files served over HTTP port 80 from a browser context, which is the mechanism used to deliver the malicious jvm.dll payload ↗
- →Alert on User-Agent strings matching MiniRedir/(5|6).(0|1|2) in HTTP logs on port 80, indicating the Windows WebDAV Mini-Redirector fetching a payload DLL ↗
- →Check for the presence of npdeploytk.dll loaded in browser processes; its existence and execution path can confirm exposure to this vulnerability ↗
- →Inspect HTML pages for OBJECT elements using MIME type 'application/npruntime-scriptable-plugin;deploymenttoolkit' or 'application/java-deployment-toolkit' calling .launch() with URL parameters containing whitespace-separated JVM flags ↗
- ·The Metasploit module requires SRVPORT=80 and URIPATH=/ to function; the WebDAV delivery mechanism will not work on non-standard ports ↗
- ·The exploit requires the target host to have the WebClient service (WebDAV Mini-Redirector) enabled; without it the UNC-path DLL loading step will fail ↗
- ·Disabling the Java browser plugin alone is insufficient mitigation because the Java Deployment Toolkit is installed independently of the plugin ↗
- ·macOS is not affected by this vulnerability; only Windows (and Linux via libnpjp2.so) are vulnerable ↗
- ·The registered MIME type for the deployment toolkit changed over time between 'application/npruntime-scriptable-plugin;deploymenttoolkit' and 'application/java-deployment-toolkit'; detections should cover both ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8wr7-r8m6-cw65: Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows r
ghsa_unreviewed·2022-05-02
CVE-2010-0886 [HIGH] GHSA-8wr7-r8m6-cw65: Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows r
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
VulnCheck
Oracle Java SE and Java for Business JDK Java Deployment Toolkit Component Vulnerability
vulncheck·2010·CVSS 10.0
CVE-2010-0886 [CRITICAL] Oracle Java SE and Java for Business JDK Java Deployment Toolkit Component Vulnerability
Oracle Java SE and Java for Business JDK Java Deployment Toolkit Component Vulnerability
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected: sun jre
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/monthly-malware-statistics-may-2010/36304/; https://www.hkcert.org/blog/large-scale-injection-incidents-targeting-oscommerce-websites
VMware
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
vendor_vmware·2011-02-10·CVSS 5.0
CVE-2008-0085 [MEDIUM] Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
VMSA-2011-0003: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory Issue date: VMware Security Advisory Updated on: VMware Security Advisory CVE numbers:
CVEs: CVE-2008-0085, CVE-2008-0086, CVE-2008-0106, CVE-2008-0107, CVE-2008-3825, CVE-2008-5416, CVE-2009-1384, CVE-2009-2693, CVE-2009-2901, CVE-2009-2902, CVE-2009-3548, CVE-2009-3555, CVE-2009-4308, CVE-2010-0003, CVE-2010-0007, CVE-2010-0008, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085,
Red Hat
Java: Java Web Start arbitrary command line injection
vendor_redhat·2010-04-09·CVSS 10.0
CVE-2010-0886 [CRITICAL] Java: Java Web Start arbitrary command line injection
Java: Java Web Start arbitrary command line injection
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Suricata
GPL EXPLOIT .cmd executable file parsing attack
suricata·2010-09-23
CVE-2000-0886 GPL EXPLOIT .cmd executable file parsing attack
GPL EXPLOIT .cmd executable file parsing attack
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT .cmd executable file parsing attack"; flow:established,to_server; http.uri; content:".cmd|22|"; nocase; pcre:"/^.*?\x26/Ri"; reference:bugtraq,1912; reference:cve,2000-0886; classtype:web-application-attack; sid:2103193; rev:6; metadata:created_at 2010_09_23, cve CVE_2000_0886, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_04_22;)
Exploit-DB
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
exploitdb·2010-09-21
CVE-2010-0886 Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
---
##
# $Id: java_ws_arginject_altjvm.rb 10404 2010-09-21 00:13:30Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Sun Java Web Start Plugin Command Line Argument Injection',
'Description' => %q{
This module exploits a flaw in the Web Start plugin component of Sun Java
Web Start. The arguments passed to Java Web Start are not properly validated.
By passing the lesser known -J option, an attacker can pass arbitrary options
directly to the Java runtime. By util
Exploit-DB
Sun Java Web Start Plugin - Command Line Argument Injection (Metasploit)
exploitdb·2010-04-09
CVE-2010-1423 Sun Java Web Start Plugin - Command Line Argument Injection (Metasploit)
Sun Java Web Start Plugin - Command Line Argument Injection (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class MetasploitModule 'Sun Java Web Start Plugin Command Line Argument Injection',
'Description' => %q{
This module exploits a flaw in the Web Start plugin component of Sun Java
Web Start. The arguments passed to Java Web Start are not properly validated.
By passing the lesser known -J option, an attacker can pass arbitrary options
directly to the Java runtime. By utilizing the -XXaltjvm option, as discussed
by Ruben Santamarta, an attacker can execute arbitrary code in the context of
an unsuspecting browser user.
This vulnerability was originally discover
Exploit-DB
JAVA Web Start - Arbitrary Command-Line Injection
exploitdb·2010-04-09
CVE-2010-0886 JAVA Web Start - Arbitrary Command-Line Injection
JAVA Web Start - Arbitrary Command-Line Injection
---
Bye bye my little 0day :(, Tavis Ormandy did a great job uncovering a big logic flaw within Java JRE. I discovered that bug and other that affects every browser few weeks ago and I posted the common "0day++" tweet.
The method in which Java Web Start support has been added to the JRE is not less than a deliberately embedded backdoor(I really don't think so) or a flagrant case of extreme negligence (+1). Let's see:
Java Plugin for Browsers (Chrome,Firefox...) - Windows: npjp2.dll (The same for IE8's jp2iexp.dll)
.text:6DAA3D96
.text:6DAA3D96 ; =============== S U B R O U T I N E =======================================
.text:6DAA3D96
.text:6DAA3D96 ; Attributes: bp-based frame
.text:6DAA3D96
.text:6DAA3D96 sub_6DAA3D96 proc near ; COD
Exploit-DB
Java Deployment Toolkit - Performs Insufficient Validation of Parameters
exploitdb·2010-04-09
CVE-2010-0886 Java Deployment Toolkit - Performs Insufficient Validation of Parameters
Java Deployment Toolkit - Performs Insufficient Validation of Parameters
---
Java Deployment Toolkit Performs Insufficient Validation of Parameters
Java Web Start (henceforth, jws) provides java developers with a way to let
users launch and install their applications using a URL to a Java Networking
Launching Protocol (.jnlp) file (essentially some xml describing the
program).
Since Java 6 Update 10, Sun has distributed an NPAPI plugin and ActiveX control
called "Java Deployment Toolkit" to provide developers with a simpler method
of distributing their applications to end users. This toolkit is installed by
default with the JRE and marked safe for scripting.
The launch() method provided by the toolkit object accepts a URL string, which
it passes to the registered handler for JNLP file
Metasploit
Sun Java Web Start Plugin Command Line Argument Injection
metasploit
Sun Java Web Start Plugin Command Line Argument Injection
Sun Java Web Start Plugin Command Line Argument Injection
This module exploits a flaw in the Web Start plugin component of Sun Java Web Start. The arguments passed to Java Web Start are not properly validated. By passing the lesser known -J option, an attacker can pass arbitrary options directly to the Java runtime. By utilizing the -XXaltjvm option, as discussed by Ruben Santamarta, an attacker can execute arbitrary code in the context of an unsuspecting browser user. This vulnerability was originally discovered independently by both Ruben Santamarta and Tavis Ormandy. Tavis reported that all versions since version 6 Update 10 "are believed to be affected by this vulnerability." In order for this module to work, it must be ran as root on a server that does not serve SMB. Additionally, th
http://lists.apple.com/archives/security-announce/2010//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//May/msg00002.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39819http://sunsolve.sun.com/search/document.do?assetkey=1-66-279590-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022294.1-1http://support.apple.com/kb/HT4170http://support.apple.com/kb/HT4171http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.htmlhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1191https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14216http://lists.apple.com/archives/security-announce/2010//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//May/msg00002.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39819http://sunsolve.sun.com/search/document.do?assetkey=1-66-279590-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022294.1-1http://support.apple.com/kb/HT4170http://support.apple.com/kb/HT4171http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.htmlhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1191https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14216
2010-04-20
Published
Exploited in the wild