Executive brief
A vulnerability in the Abstract Window Toolkit (AWT) component of Oracle Java SE could allow a remote attacker to take over a user's system. This issue primarily affects desktop users running untrusted Java content, such as web applets or Java Web Start applications, in a browser. An exploit requires a user to interact with a malicious website or application, which could then bypass security protections to access sensitive data or disrupt operations.
Technical details
A vulnerability exists in the AWT (Abstract Window Toolkit) subcomponent of Oracle Java SE. The flaw is difficult to exploit and requires human interaction (User Interaction: Required) from a person other than the attacker. It specifically impacts client-side deployments that run untrusted code within the Java sandbox, such as Java Web Start applications or applets. A successful exploit allows an unauthenticated attacker with network access to bypass sandbox restrictions, potentially leading to a complete takeover of the Java SE environment and impacting the underlying host system (Scope: Changed). Affected versions include Java SE 7u121 and 8u112. Patches are available through the Oracle January 2017 Critical Patch Update.
Affected products
- Oracle Java SE 7u121, 8u112
- Oracle OpenJDK 7u121-2.6.8-2~deb8u1
- Gentoo IcedTea < 7.2.6.10, < 3.4.0
Timeline
- 2017-01-25: advisory: Oracle Critical Patch Update released
- 2017-01-27: disclosed: NVD publication date
- 2017-02-08: patched: Debian security update for openjdk-7 released
References
- http://www.debian.org/security/2017/dsa-3782
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
- http://www.securityfocus.com/bid/95576
- http://www.securitytracker.com/id/1037637
- https://security.gentoo.org/glsa/201701-65
- https://security.gentoo.org/glsa/201707-01
- https://security.netapp.com/advisory/ntap-20170119-0001/