⚠ Actively exploited
Added to CISA KEV on 2022-03-03. Federal agencies required to patch by 2022-03-24. Required action: Apply updates per vendor instructions..

CVE-2011-3544

Severity
9.8CRITICAL
EPSS
92.5%
top 0.26%
CISA KEV
KEV
Added 2022-03-03
Due 2022-03-24
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 19
KEV addedMar 3
KEV dueMar 24
Latest updateMay 14
CISA Required Action: Apply updates per vendor instructions.

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Also affects: Ubuntu Linux 10.04, 10.10, 11.04, 11.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-25jq-3vh4-pgv4: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untruste2022-05-14
CVEList
CVE-2011-3544: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untruste2011-10-19
VulnCheck
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability2011

💥Exploits & PoCs

1
Exploit-DB
Java Applet Rhino Script Engine - Remote Code Execution (Metasploit)2011-11-30

🔍Detection Rules

2
Suricata
ET MALWARE Dooptroop CnC Beacon2012-01-10
Suricata
ET MALWARE Dooptroop Dropper Checkin2011-04-07

📋Vendor Advisories

3
CISA
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability2022-03-03
Ubuntu
IcedTea-Web, OpenJDK 6 vulnerabilities2011-11-16
Red Hat
OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)2011-10-18

💬Community

1
Bugzilla
CVE-2011-3544 OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)2011-10-12
CVE-2011-3544 (CRITICAL CVSS 9.8) | Unspecified vulnerability in the Ja | cvebase.io