ZeroHour

CVE-2011-3544

KEVmass

Remote Code Execution in Oracle Java SE JRE Applet Rhino Script Engine

CISA: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVSS
EPSS
97%p100
Published
KEV added
AI analysis

CVE-2011-3544 is an access control flaw in the Rhino JavaScript Script Engine component used by Java applets in Oracle's Java Runtime Environment. It is triggered when a user's browser loads a malicious Java applet, allowing script executed through the Rhino engine to bypass Java's access restrictions. An attacker who successfully exploits it gains the ability to run arbitrary code on the victim's machine with the privileges of the logged-in user, typically via drive-by download from a compromised or attacker-controlled website. Any system with a vulnerable Oracle Java SE JDK or JRE and an enabled Java browser plugin is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-03-03, carries a 96.7% EPSS probability of exploitation within 30 days, and contemporary reports show it weaponized in the BlackHole/Whitehole exploit kits and used in mass OS X exploitation.

What to do: Apply updated Oracle Java SE builds per Oracle's vendor instructions, prioritizing internet-facing and end-user systems listed in the KEV guidance. Where patching is delayed, disable the Java browser plugin or block Java applets at the web gateway, since the attack vector is malicious applets served over the web. Review endpoints for signs of exploit-kit drive-by compromise, especially legacy Windows and OS X machines with outdated Java.

Affected
Oracle Java SE JDK and JRE
Estimated exposure
masshundreds of millions of desktops and servers with a Java runtime installed; exact count unknown — Oracle Java runtimes and the browser plugin were near-ubiquitous on enterprise desktops and servers at the time, and the top-percentile EPSS plus widespread adoption in drive-by exploit kits indicate a very large installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Oracle Java SE JDK and JRE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Oracle
Products
Java SE JDK and JRE

In the news