CVE-2010-3552
published 2010-10-19CVE-2010-3552: Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect…
PriorityP184critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
80.74%
99.6th percentile
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Oracle Java 6 Object Tag launchjnlp docbase Parameters Buffer Overflow"; flow:established,to_client; flowbits:isset,NtDll.ImageBase.Module.Called; file.data; content:"ZwProtectVirtualMemory|22|"; fast_pattern; content:"strDup|28|"; distance:0; content:"<object|20|"; distance:0; content:"application|2f|x|2d|java|2d|applet"; within:35; content:"|3c|param|20|name"; distance:0; content:"|22|launchjnlp|22|"; within:20; content:"|3c|param|20|name"; distance:0; content:"|22|docbase|22|"; within:20; content:"|3c|fieldset|3e 3c|legend|3e|"; distance:0; content:"object"; within:10; content:"|2e|innerHTML"; distance:0; reference:url,www.exploit-db.com/exploits/15241/; reference:cve,2010-3552; reference:bid,44023; classtype:attempted-user; sid:2012100; rev:8; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_12_22, cve CVE_2010_3552, deployment Perimeter, confidence High, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_09;)
- →Exploit triggers when a Java OBJECT tag is invoked with both 'launchjnlp' and 'docbase' parameters; the docbase value of 396+ bytes overflows a 256-byte stack buffer via sprintf. ↗
- →Exploit payload relies on ROP gadgets from msvcr71.dll (base 0x7c340000) bundled with JRE 6; presence of MSVCR71.dll loaded from the JRE bin directory is a host-side indicator. ↗
- →DEP-bypass variant uses ZwProtectVirtualMemory calls combined with a heap spray; network detection should look for 'ZwProtectVirtualMemory' string alongside launchjnlp/docbase OBJECT tag parameters in HTTP responses. ↗
- →The Metasploit module uses 'migrate -f' as InitialAutoRunScript; post-exploitation process migration from the Java process is an expected behavioral indicator. ↗
- →CVE-2010-3552 was observed being served alongside CVE-2010-4452 by the Blackhole Exploit Kit from a compromised USPS.gov website, alongside malicious JAR and PDF payloads. ↗
- →Bad characters for the overflow payload are null bytes, double-quotes, and the range 0x80–0x9F (due to WideCharToMultiByte conversion); payloads containing these bytes in the docbase parameter are not valid exploit attempts. ↗
- ·The vulnerability affects all JRE 6 versions from Update 10 through Update 21 (inclusive); Update 22 and later are patched. ↗
- ·The exploit only works on Windows targets; the Metasploit module platform is set to 'win' only. ↗
- ·The SkyLined DEP-bypass variant does not bypass ASLR; on ASLR-enabled targets the ntdll base address must be supplied or brute-forced. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_cisco6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK unspecified vulnerability in New Java Plugin component
vendor_redhat·2010-10-12·CVSS 10.0
CVE-2010-3552 [CRITICAL] JDK unspecified vulnerability in New Java Plugin component
JDK unspecified vulnerability in New Java Plugin component
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Cisco
MIT Kerberos GSS-API Library Remote Denial of Service Vulnerability
vendor_cisco·2010-05-19·CVSS 6.8
CVE-2010-1321 [MEDIUM] CWE-399 MIT Kerberos GSS-API Library Remote Denial of Service Vulnerability
MIT Kerberos GSS-API Library Remote Denial of Service Vulnerability
MIT Kerberos contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is in the GSS-API acceptor component due to lack of pointer validation. An authenticated, remote attacker could exploit the vulnerability by making a crafted request to the affected component. This action could cause the component to crash, resulting in a DoS condition.
MIT has confirmed this vulnerability and released updated software.
The vulnerability can be exploited only by an authenticated attacker, which somewhat reduces the threat of an attack on affected systems.
Cisco Network Admission Control Guest Server may be affected if Active Directory single sign-on is
GHSA
GHSA-3rv7-vfgw-fvwj: Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect conf
ghsa_unreviewed·2022-05-17
CVE-2010-3552 [HIGH] GHSA-3rv7-vfgw-fvwj: Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect conf
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
VulnCheck
Oracle Java SE and Java for Business New Java Plug-in Component Vulnerability
vulncheck·2010·CVSS 10.0
CVE-2010-3552 [CRITICAL] Oracle Java SE and Java for Business New Java Plug-in Component Vulnerability
Oracle Java SE and Java for Business New Java Plug-in Component Vulnerability
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected: sun jre
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/max-sets-its-sights-on-x64-platforms/29672/
Suricata
ET WEB_CLIENT Oracle Java 6 Object Tag launchjnlp docbase Parameters Buffer Overflow
suricata·2010-12-22
CVE-2010-3552 ET WEB_CLIENT Oracle Java 6 Object Tag launchjnlp docbase Parameters Buffer Overflow
ET WEB_CLIENT Oracle Java 6 Object Tag launchjnlp docbase Parameters Buffer Overflow
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Oracle Java 6 Object Tag launchjnlp docbase Parameters Buffer Overflow"; flow:established,to_client; flowbits:isset,NtDll.ImageBase.Module.Called; file.data; content:"ZwProtectVirtualMemory|22|"; fast_pattern; content:"strDup|28|"; distance:0; content:"<object|20|"; distance:0; content:"application|2f|x|2d|java|2d|applet"; within:35; content:"|3c|param|20|name"; distance:0; content:"|22|launchjnlp|22|"; within:20; content:"|3c|param|20|name"; distance:0; content:"|22|docbase|22|"; within:20; content:"|3c|fieldset|3e 3c|legend|3e|"; distance:0; content:"object"; within:10; content:"|2e|innerHTML"; distance:0; reference:url,www.exploit-
Exploit-DB
Sun Java - Runtime New Plugin docbase Buffer Overflow (Metasploit)
exploitdb·2011-01-08
CVE-2010-3552 Sun Java - Runtime New Plugin docbase Buffer Overflow (Metasploit)
Sun Java - Runtime New Plugin docbase Buffer Overflow (Metasploit)
---
##
# $Id: java_docbase_bof.rb 11513 2011-01-08 00:25:44Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Sun Java Runtime New Plugin docbase Buffer Overflow',
'Description' => %q{
This module exploits a flaw in the new plugin component of the Sun Java
Runtime Environment before v6 Update 22. By specifying specific parameters
to the new plugin, an attacker can cause a stack-based buffer overflow and
execute arbitrary code.
When the new plugin is invoked with a "l
Exploit-DB
Oracle Java 6 - OBJECT tag 'launchjnlp'/'docbase' Remote Buffer Overflow
exploitdb·2010-10-13
CVE-2010-3552 Oracle Java 6 - OBJECT tag 'launchjnlp'/'docbase' Remote Buffer Overflow
Oracle Java 6 - OBJECT tag 'launchjnlp'/'docbase' Remote Buffer Overflow
---
Source: http://code.google.com/p/skylined/issues/detail?id=23
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
,dSSSSSSSSSSSS SSSS ,dSSY' SSSS SSSS SSSS SSSS SSSSb, SSSS ,dSSSSSSSSSSSS SSSSSSSSSSSSb,
SSSS SSSS ,dSSY' SSSS SSSS SSSS SSSS SSSSSSb, SSSS SSSS SSSS SSSS
'YSSSSSSSSSSb, SSSSSSSSSSSSb, 'YSSSSSSSSSSSS SSSS SSSS SSSS'YSSb,SSSS SSSSSSSSSSS SSSS SSSS
SSSS SSSS SSSS SSSS SSSS SSSS SSSS 'YSSSSSS SSSS SSSS SSSS
SSSSSSSSSSSSP' SSSS SSSS SSSSSSSSSSSSP' 'YSSSSSSSSSS SSSS SSSS 'YSSSS 'YSSSSSSSSSSSS SSSS SSSSSSP'
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
Internet Exploiter
Metasploit
Sun Java Runtime New Plugin docbase Buffer Overflow
metasploit
Sun Java Runtime New Plugin docbase Buffer Overflow
Sun Java Runtime New Plugin docbase Buffer Overflow
This module exploits a flaw in the new plugin component of the Sun Java Runtime Environment before v6 Update 22. By specifying specific parameters to the new plugin, an attacker can cause a stack-based buffer overflow and execute arbitrary code. When the new plugin is invoked with a "launchjnlp" parameter, it will copy the contents of the "docbase" parameter to a stack-buffer using the "sprintf" function. A string of 396 bytes is enough to overflow the 256 byte stack buffer and overwrite some local variables as well as the saved return address. NOTE: The string being copied is first passed through the "WideCharToMultiByte". Due to this, only characters which have a valid localized multibyte representation are allowed. Invalid characters
Bugzilla
CVE-2010-3552 JDK unspecified vulnerability in New Java Plugin component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3552 [CRITICAL] CVE-2010-3552 JDK unspecified vulnerability in New Java Plugin component
CVE-2010-3552 JDK unspecified vulnerability in New Java Plugin component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the New Java Plugin component (CVE-2010-3552). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
Bugzilla
CVE-2009-3552 GUI: Man in the middle attack possible on the GUI to Backend SSL connection
bugzilla·2009-10-14·CVSS 3.1
CVE-2009-3552 [LOW] CVE-2009-3552 GUI: Man in the middle attack possible on the GUI to Backend SSL connection
CVE-2009-3552 GUI: Man in the middle attack possible on the GUI to Backend SSL connection
It was found that the SSL certificate was not verified when using the
client-side Red Hat Enterprise Virtualization Manager interface (a Windows
Presentation Foundation (WPF) XAML browser application) to connect to the Red
Hat Enterprise Virtualization Manager. An attacker on the local network could
use this flaw to conduct a man-in-the-middle attack, tricking the user into
thinking they are viewing the Red Hat Enterprise Virtualization Manager when the
content is actually attacker-controlled, or modifying actions a user requested
Red Hat Enterprise Virtualization Manager to perform.
Discussion:
This issue has been addressed in following products:
Via RHSA-2010:0613 https://rhn.redhat.com/errata/
Zscaler
USPS.gov Website Infected with Blackhole EK | Zscaler Blog
blogs_zscaler·2011-04-07·CVSS 10.0
[CRITICAL] USPS.gov Website Infected with Blackhole EK | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://support.avaya.com/css/P8/documents/100114315http://support.avaya.com/css/P8/documents/100123193http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0770.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11829https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12004http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://support.avaya.com/css/P8/documents/100114315http://support.avaya.com/css/P8/documents/100123193http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0770.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11829https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12004
2010-10-19
Published
Exploited in the wild