Junglewise Threat Intelligence

CVE-2017-3272: Oracle Java SE insufficient protected field access checks in Libraries

CVE-2017-3272 · Severity: critical · CVSS 9.6 · Published 2017-01-27

Technologies: Oracle Java SE, Oracle Java SE Embedded. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Java SE and Java SE Embedded that could allow an attacker to take complete control of a user's system. This issue primarily affects desktop users running Java applications or applets from the internet that rely on the Java 'sandbox' for security. An exploit requires a user to interact with a malicious website or application, which could then lead to the theft of sensitive data or the installation of malware.

Technical details

This vulnerability is classified as an insufficient protected field access check within the atomic field updaters of the Java Libraries subcomponent. It is easily exploitable by an unauthenticated attacker with network access via multiple protocols, though it requires human interaction (User Interaction: Required) to succeed. The flaw primarily impacts Java deployments that run untrusted code, such as sandboxed Java Web Start applications or applets. Successful exploitation can result in a complete compromise of the Java environment and may significantly impact additional products (Scope: Changed). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Java SE 6u131, 7u121, 8u112
  • Oracle Java SE Embedded 8u111

Timeline

  • 2017-01-19: patched: Oracle released patches as part of the January 2017 Critical Patch Update.
  • 2017-01-27: disclosed: Initial public disclosure.

References

Related threats