CVE-2017-3241
Description
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS v3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).
In plain language
AI Worth attentionCVE-2017-3241 is a serious Java vulnerability that can let someone on the network remotely take over vulnerable Java (including JRockit) versions; small businesses should act if they run any affected Java with network-exposed services.
CVE-2017-3241 is an unauthenticated, network-reachable Java RMI weakness (CWE-20: input validation failure) in Java SE / Java SE Embedded / JRockit that can allow remote compromise by sending crafted data through Java APIs (commonly via a web service).
What to do now
- Check which Java you run (Java SE / Java SE Embedded / JRockit) and confirm whether your version matches 6u131, 7u121, 8u112, or Java SE Embedded 8u111, or JRockit R28.3.12.
- Verify whether your Java is reachable from the network through a service that can pass data into Java APIs (for example, a web service using Java/RMI).
- Upgrade Java to the version(s) provided in Oracle’s remediation for CVE-2017-3241 (Oracle CPU for January 2017) and restart the affected services.
- If you cannot upgrade immediately, restrict network access to the Java services that accept requests and ensure they are not exposed to untrusted networks.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-3241 and every CVE in our database. Create a free account — no credit card required.
Create Free Account