CVE-2011-3544
published 2011-10-19CVE-2011-3544: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java…
PriorityP194critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
96.71%
99.9th percentile
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| oracle | jdk | < 1.6.0 | 1.6.0 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | < 1.6.0 | 1.6.0 |
| oracle | jre | — | — |
| oracle | jre | — | — |
| redhat | satellite_with_embedded_oracle | — | — |
| suse | linux_enterprise_java | — | — |
| suse | linux_enterprise_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs: 31229-31232
- →The Bleeding Life exploit kit serving CVE-2011-3544 delivers a JAR file via URI path matching /modules/1.jar; landing page URIs follow the pattern /load_module.php?user=(n1|11?|2) ↗
- →The Metasploit module for CVE-2011-3544 serves a JAR file (Applet.jar) containing Exploit.class; HTTP response Content-Type is application/octet-stream for the JAR and text/html for the landing page containing a Java applet tag ↗
- →The Metasploit exploit module for CVE-2011-3544 generates an HTML page with 'Loading, Please Wait...' as the applet loader text; this string can be used as a network content signature ↗
- →The Flashback.I macOS trojan exploits CVE-2011-3544; C&C domains observed include bodyrocks.rr.nu, femalebodyinspector.rr.nu, and johncartermovie2012.com ↗
- →CVE-2011-3544 exploits are shared between the Bleeding Life and Nuclear exploit kits; the same JAR hash (3C3172A4...) appears in both kits ↗
- ·The Flashback.I trojan has web-inject capability to modify pages viewed in Safari based on a C&C-delivered configuration file; the exact web-inject targets were not confirmed at time of reporting ↗
- ·Twitter-based C&C for an early Flashback variant was reported but never confirmed as actually used by the botherder ↗
- ·The CVE-2011-3544 Metasploit module targets Java 7 and Java 6 Update 27 and earlier across multiple platforms (Windows, Linux, macOS) and browsers supporting Java ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
cisa·2022-03-03·CVSS 9.8
CVE-2011-3544 [CRITICAL] Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Vulnerability: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Affected: Oracle Java SE JDK and JRE
An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2011-3544
Remediation Due Date: 2022-03-24
Ubuntu
OpenJDK 6 regression
vendor_ubuntu·2012-01-24·CVSS 4.3
CVE-2011-3389 [MEDIUM] OpenJDK 6 regression
Title: OpenJDK 6 regression
Summary: USN-1263-1 caused a regression when using OpenJDK 6's SSL/TLS
implementation.
USN-1263-1 fixed vulnerabilities in OpenJDK 6. The upstream patch for
the chosen plaintext attack on the block-wise AES encryption algorithm
(CVE-2011-3389) introduced a regression that caused TLS/SSL connections
to fail when using certain algorithms. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)
implementation in the IcedTea web browser plugin. This could allow a
remote attacker to open connections to certain hosts that should
not be permitted. (CVE-2011-3377)
Juliano Rizzo and Thai Duong discovered that the block-wise AES
encryption algorithm block-wise as use
Ubuntu
IcedTea-Web, OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-11-16·CVSS 4.3
CVE-2011-3389 [MEDIUM] IcedTea-Web, OpenJDK 6 vulnerabilities
Title: IcedTea-Web, OpenJDK 6 vulnerabilities
Summary: Multiple OpenJDK 6 and IcedTea-Web vulnerabilities have been fixed.
Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)
implementation in the IcedTea web browser plugin. This could allow a
remote attacker to open connections to certain hosts that should
not be permitted. (CVE-2011-3377)
Juliano Rizzo and Thai Duong discovered that the block-wise AES
encryption algorithm block-wise as used in TLS/SSL was vulnerable to
a chosen-plaintext attack. This could allow a remote attacker to view
confidential data. (CVE-2011-3389)
It was discovered that a type confusion flaw existed in the in
the Internet Inter-Orb Protocol (IIOP) deserialization code. A
remote attacker could use this to cause an untrusted application
or applet to
Red Hat
OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)
vendor_redhat·2011-10-18·CVSS 9.8
CVE-2011-3544 [CRITICAL] OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)
OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 4) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 4) - Not affected
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.4.2-ibm-sap (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-25jq-3vh4-pgv4: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untruste
ghsa_unreviewed·2022-05-14
CVE-2011-3544 [HIGH] CWE-284 GHSA-25jq-3vh4-pgv4: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untruste
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
VulnCheck
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
vulncheck·2011·CVSS 9.8
CVE-2011-3544 [CRITICAL] Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
Affected: Oracle Java SE JDK and JRE
Required Action: Apply updates per vendor instructions.
Exploitation References: https://isc.sans.edu/diary/12400; https://web.archive.org/web/20120304003736/http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/reports/rpt_a-look-back-at-2011_information-is-currency.pdf; https://securelist.com/red-october-diplomatic-cyber-attacks-investigation/36740/; https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2013/hidden_lynx.pdf; https://www.secureworks.com/research/threat-grou
Suricata
ET MALWARE Dooptroop CnC Beacon
suricata·2012-01-10
CVE-2011-3544 ET MALWARE Dooptroop CnC Beacon
ET MALWARE Dooptroop CnC Beacon
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Dooptroop CnC Beacon"; flow:established,to_server; http.method; content:"GET"; http.uri; content:".php?num="; fast_pattern; content:"&rev="; distance:0; pcre:"/^\/[a-z]+\.php\?num=\d+&rev=/"; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,blog.eset.com/2012/03/17/drive-by-ftp-a-new-view-of-cve-2011-3544; classtype:command-and-control; sid:2014112; rev:7; metadata:attack_target Client_Endpoint, created_at 2012_01_10, deployment Perimeter, signature_severity Major, tag c2, updated_at 2024_04_20, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel;)
Suricata
ET MALWARE Dooptroop Dropper Checkin
suricata·2011-04-07
CVE-2011-3544 ET MALWARE Dooptroop Dropper Checkin
ET MALWARE Dooptroop Dropper Checkin
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Dooptroop Dropper Checkin"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/nconfirm.php?"; fast_pattern; content:"rev="; distance:0; content:"code="; content:"param="; content:"num="; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,blog.eset.com/2012/03/17/drive-by-ftp-a-new-view-of-cve-2011-3544; classtype:command-and-control; sid:2013808; rev:6; metadata:created_at 2011_04_07, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_20;)
Exploit-DB
Java Applet Rhino Script Engine - Remote Code Execution (Metasploit)
exploitdb·2011-11-30·CVSS 9.8
CVE-2011-3544 [CRITICAL] Java Applet Rhino Script Engine - Remote Code Execution (Metasploit)
Java Applet Rhino Script Engine - Remote Code Execution (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
require 'rex'
class Metasploit3 'Java Applet Rhino Script Engine Remote Code Execution',
'Description' => %q{
This module exploits a vulnerability in the Rhino Script Engine that
can be used by a Java Applet to run arbitrary Java code outside of
the sandbox. The vulnerability affects version 7 and version 6 update
27 and earlier, and should work on any browser that supports Java
(for example: IE, Firefox, Google Chrome, etc)
},
'License' => MSF
Metasploit
Java Applet Rhino Script Engine Remote Code Execution
metasploit
Java Applet Rhino Script Engine Remote Code Execution
Java Applet Rhino Script Engine Remote Code Execution
This module exploits a vulnerability in the Rhino Script Engine that can be used by a Java Applet to run arbitrary Java code outside of the sandbox. The vulnerability affects version 7 and version 6 update 27 and earlier, and should work on any browser that supports Java (for example: IE, Firefox, Google Chrome, etc)
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
- Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
1. Was our software used outside of its intended functionality to pull classified information from a person’s c
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
Was our software used outside of its intended functionality to pull classified information from a person’s comput
Talos
The never ending Exploit Kit shift - Bleeding Life
blogs_talos·2014-06-12·CVSS 9.8
[CRITICAL] The never ending Exploit Kit shift - Bleeding Life
## The never ending Exploit Kit shift - Bleeding Life
Recently we've been able to observe several shifts in exploit kit techniques, so I thought it would be good to share the IOC information for the exploit kits so that administrators and network defenders can take a look at their devices and logs to remediate on their networks.
## Bleeding Life
Bleeding life, traditionally, was not one of the more subtle exploit kits.
In the past, the exploit kit would attempt to get the exploits through fairly obvious URI methods. For example:
"/load_module.php?e=Adobe-2010-2884"
"/load_module.php?e=Java-2010-3552"
"/modules/helpers/Java-2010-0842.jar"
The URI would be explicit about which vulnerability the kit was going to download and run on the client. However, as of the beginning of of May, s
Talos
The never ending Exploit Kit shift - Bleeding Life
blogs_talos·2014-06-12·CVSS 9.8
[CRITICAL] The never ending Exploit Kit shift - Bleeding Life
Recently we've been able to observe several shifts in exploit kit techniques, so I thought it would be good to share the IOC information for the exploit kits so that administrators and network defenders can take a look at their devices and logs to remediate on their networks.
## Bleeding Life
Bleeding life, traditionally, was not one of the more subtle exploit kits.
In the past, the exploit kit would attempt to get the exploits through fairly obvious URI methods. For example:
"/load_module.php?e=Adobe-2010-2884"
"/load_module.php?e=Java-2010-3552"
"/modules/helpers/Java-2010-0842.jar"
The URI would be explicit about which vulnerability the kit was going to download and run on the client. However, as of the beginning of of May, subtlety increased slightly, as we've seen a shift in th
Zscaler
Mac OSX Flashback Confusion And Hype | Zscaler
blogs_zscaler·2012-04-06
Mac OSX Flashback Confusion And Hype | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
arXiv
Cream Skimming the Underground: Identifying Relevant Information Points from Online Forums
arxiv_fulltext·2023-08-03
Cream Skimming the Underground: Identifying Relevant Information Points from Online Forums
Cream Skimming the Underground: Identifying Relevant Information Points from Online Forums
Felipe Moreno-Vera, Mateus Nogueira, Daniel S. Menasché, Miguel Bicudo, Ashton Woiwood, Enrico Lovat, Anton Kocheturov, and Leandro Pfleger de Aguiar
[1]
Felipe Moreno-Vera1, Mateus Nogueira1, Cainã Figueiredo1, Daniel S. Menasché1, Miguel Bicudo1,
Ashton Woiwood2, Enrico Lovat3, Anton Kocheturov3, and Leandro Pfleger de Aguiar4
1Federal University of Rio de Janeiro (UFRJ),
3Siemens Corporation, 2ESO,
4Amazon.com
[1]
(#1)
footnote-1
plain
plain
## Abstract
This paper proposes a machine learning-based approach for detecting the exploitation of vulnerabilities in the wild by monitoring underground hacking forums. The increasing volume of posts discussing exploitation in the wild calls for an
Bugzilla
CVE-2011-3544 OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)
bugzilla·2011-10-12·CVSS 9.8
CVE-2011-3544 [CRITICAL] CVE-2011-3544 OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)
CVE-2011-3544 OpenJDK: missing SecurityManager checks in scripting engine (Scripting, 7046823)
It was discovered that Java ScriptingEngine did not implement required SecurityManager checks. A malicious applet or application should use this flaw to bypass SecurityManager restriction and execute arbitrary code with the privileges of Java Virtual Machine.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2011:1380 https://rhn.redhat.com/errata/RHSA-2011-1380.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlhttp://marc.info/?l=bugtraq&m=132750579901589&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48308http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/developerworks/java/jdk/alerts/http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1384.htmlhttp://www.securityfocus.com/bid/50218http://www.securitytracker.com/id?1026215http://www.ubuntu.com/usn/USN-1263-1https://exchange.xforce.ibmcloud.com/vulnerabilities/70849https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13947http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlhttp://marc.info/?l=bugtraq&m=132750579901589&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48308http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/developerworks/java/jdk/alerts/http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1384.htmlhttp://www.securityfocus.com/bid/50218http://www.securitytracker.com/id?1026215http://www.ubuntu.com/usn/USN-1263-1https://exchange.xforce.ibmcloud.com/vulnerabilities/70849https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13947https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-3544
2011-10-19
Published
2022-03-03
Added to CISA KEV
Exploited in the wild