cbcvebase.
CVE-2011-3544
published 2011-10-19

CVE-2011-3544: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java…

PriorityP194critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
96.71%
99.9th percentile
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
oraclejdk< 1.6.01.6.0
oraclejdk
oraclejdk
oraclejre< 1.6.01.6.0
oraclejre
oraclejre
redhatsatellite_with_embedded_oracle
suselinux_enterprise_java
suselinux_enterprise_server

Detection & IOCsextracted from sources · hover to see the quote

hash3C3172A47915FE77EF1F2D38CCB5C786D30F13D8C5161FD0F2411C3B0459A036
path/load_module.php?user=
path/modules/1.jar
pathdata/exploits/cve-2011-3544
filenameExploit.class
snort
SIDs: 31229-31232
  • The Bleeding Life exploit kit serving CVE-2011-3544 delivers a JAR file via URI path matching /modules/1.jar; landing page URIs follow the pattern /load_module.php?user=(n1|11?|2)
  • The Metasploit module for CVE-2011-3544 serves a JAR file (Applet.jar) containing Exploit.class; HTTP response Content-Type is application/octet-stream for the JAR and text/html for the landing page containing a Java applet tag
  • The Metasploit exploit module for CVE-2011-3544 generates an HTML page with 'Loading, Please Wait...' as the applet loader text; this string can be used as a network content signature
  • The Flashback.I macOS trojan exploits CVE-2011-3544; C&C domains observed include bodyrocks.rr.nu, femalebodyinspector.rr.nu, and johncartermovie2012.com
  • CVE-2011-3544 exploits are shared between the Bleeding Life and Nuclear exploit kits; the same JAR hash (3C3172A4...) appears in both kits
  • ·The Flashback.I trojan has web-inject capability to modify pages viewed in Safari based on a C&C-delivered configuration file; the exact web-inject targets were not confirmed at time of reporting
  • ·Twitter-based C&C for an early Flashback variant was reported but never confirmed as actually used by the botherder
  • ·The CVE-2011-3544 Metasploit module targets Java 7 and Java 6 Update 27 and earlier across multiple platforms (Windows, Linux, macOS) and browsers supporting Java

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.