CVE-2010-0840

Oracle Java Runtime Environment (JRE): JRE Unspecified

As of , CVE-2010-0840 in Oracle Java Runtime Environment (JRE) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 25 May 2022
US federal deadline
15 June 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.96Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.84 on 25 May 2022EPSS on the day CISA listed it.
Public exploit
1 Metasploit module and 1 Exploit-DB entry (1 verified)
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.

CISA's description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."

The CVE record's description, from oracle

CVE published
1 April 2010
Assigned by
oracle
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 16297).
  3. CISA added it to its list of exploited vulnerabilities.
  4. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Java Runtime Environment (JRE): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2013-0422JRE Remote Code ExecutionOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2013-0431JRE Sandbox BypassOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
CVE-2013-2423JRE UnspecifiedOracle Java Runtime Environment (JRE)Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry0.85

Read further