Java 0-day vulnerability discovered for the first time in two years
Oracle recently announced the first Java 0-day vulnerability in the past two years. It affects the Java Web Start application sandbox and Java applets sandbox. Considering that the vulnerability is being exploited and is easy to develop, the vulnerability is rated at the highest risk level according to the CVSS (general vulnerability scoring system. Oracle has released a patch and urged customers to upgrade as soon as possible.
The vulnerability was identified as a CVE-2015-2590 that Trend Micro's smart protection network was found after analyzing emails from NATO Member States and the US Defense Organization. These emails contain links that point to the Java applets website. These Java applets exploit these vulnerabilities to allow remote code execution on the victim's computer.
It is important to know that this vulnerability does not affect the entire Java Runtime Environment, but only the Java Web Start Program and Java applets. It does not affect the applications deployed on the server, or even the Java applications deployed on local clients. This means that users will not be in danger as long as they do not navigate to websites containing such applications. However, for those who have already performed dangerous operations, Oracle determines two levels of risks based on user attributes.
This vulnerability allows users in the activity to execute code. Therefore, the impact of this vulnerability depends on whether the user has administrator permissions. In Linux and Solaris systems, there are also Windows systems, such as Windows Vista or later systems, users usually do not have administrator permissions (in Windows Vista and later systems, the user may have such permissions, but a clear confirmation is required to enter the elevation mode to obtain administrator permissions). In this case, the CVSS score of Oracle is 7.5 (total score: 10 ). However, some systems, such as Windows XP, still account for a large proportion of users who are generally standard users and the system grants them administrator privileges directly. This makes them very vulnerable to remote code execution attacks. In this case, the Oracle score is 10 points (total score: 10 points ).
Oracle released a fix for this vulnerability in July 14 and updated it as part of their CPU plan or as a key patch. The CPU version is released once every quarter, and each time it contains the vulnerability fix for the previous quarter. It is likely that the vulnerability was discovered shortly before the scheduled update time, so the vulnerability was fixed as part of the planned upgrade. If the vulnerability was discovered at other times, Oracle is likely to release a security warning update beyond the planned level, just like a vulnerability CVE-2013-1493 that once occurred.
This article permanently updates the link address: