Executive brief
A critical vulnerability exists in the Hotspot component of Oracle Java SE, which is used to run Java applications on computers and embedded devices. If a user is tricked into running malicious Java code—such as through a compromised website or a sandboxed applet—an attacker could bypass security protections to take full control of the system. This issue primarily affects desktop users and clients that run untrusted code from the internet, rather than secured server environments.
Technical details
This vulnerability, classified as 'insecure class construction' within the Hotspot subcomponent, allows an unauthenticated attacker with network access to compromise the Java Runtime Environment. The exploit is triggered when a user runs untrusted, sandboxed Java code (such as Java Web Start applications or applets) that leverages this flaw to escape the Java sandbox. Successful exploitation results in a complete takeover of the Java SE or Java SE Embedded instance, potentially impacting the underlying host system. The vulnerability is easily exploitable but requires human interaction, such as a user visiting a malicious webpage. Oracle addressed this in the January 2017 Critical Patch Update (CPU).
Affected products
- Oracle Java SE 7u121, 8u112
- Oracle Java SE Embedded 8u111
Timeline
- 2017-01-19: patched: Red Hat released security updates for RHEL 5, 6, and 7.
- 2017-01-27: disclosed: Initial public disclosure.
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://rhn.redhat.com/errata/RHSA-2017-0176.html
- http://rhn.redhat.com/errata/RHSA-2017-0180.html
- http://rhn.redhat.com/errata/RHSA-2017-0263.html
- http://rhn.redhat.com/errata/RHSA-2017-0269.html
- http://rhn.redhat.com/errata/RHSA-2017-0336.html
- http://rhn.redhat.com/errata/RHSA-2017-0337.html