#VU8080 Arbitrary code execution in Oracle Java SE


Published: 2017-09-05

Vulnerability identifier: #VU8080

Vulnerability risk: Medium

CVSSv3.1: 6.2 [CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-10125

CWE-ID: CWE-264

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Oracle Java SE
Universal components / Libraries / Software for developers

Vendor: Oracle

Description
The vulnerability allows an attacker with physical access to the system to execute arbitrary code on the target system.

The weakness exists due to unknown error. A remote attacker can execute arbitrary code with elevated privileges and compromise the vulnerable system.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Oracle Java SE: 8u131, 7u141


External links
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability