Junglewise Threat Intelligence

CVE-2017-3260: Oracle Java SE sandbox bypass in AWT

CVE-2017-3260 · Severity: high · CVSS 8.3 · Published 2017-01-27

Technologies: Oracle Java SE. Vendors: Oracle.

Executive brief

A vulnerability in the Abstract Window Toolkit (AWT) component of Oracle Java SE could allow a remote attacker to take over a user's system. This issue primarily affects desktop users running untrusted Java content, such as web applets or Java Web Start applications, in a browser. An exploit requires a user to interact with a malicious website or application, which could then bypass security protections to access sensitive data or disrupt operations.

Technical details

A vulnerability exists in the AWT (Abstract Window Toolkit) subcomponent of Oracle Java SE. The flaw is difficult to exploit and requires human interaction (User Interaction: Required) from a person other than the attacker. It specifically impacts client-side deployments that run untrusted code within the Java sandbox, such as Java Web Start applications or applets. A successful exploit allows an unauthenticated attacker with network access to bypass sandbox restrictions, potentially leading to a complete takeover of the Java SE environment and impacting the underlying host system (Scope: Changed). Affected versions include Java SE 7u121 and 8u112. Patches are available through the Oracle January 2017 Critical Patch Update.

Affected products

  • Oracle Java SE 7u121, 8u112
  • Oracle OpenJDK 7u121-2.6.8-2~deb8u1
  • Gentoo IcedTea < 7.2.6.10, < 3.4.0

Timeline

  • 2017-01-25: advisory: Oracle Critical Patch Update released
  • 2017-01-27: disclosed: NVD publication date
  • 2017-02-08: patched: Debian security update for openjdk-7 released

References

Related threats