LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2011-3544: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2011-3544 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

CVE-2011-3544 is an access control vulnerability in the Applet Rhino Script Engine component of Oracle Java SE JDK and JRE. It allows a remote attacker to execute arbitrary code on systems running the affected runtime. For IT and security teams, this matters because Java runtimes are widely deployed on endpoints and servers; successful abuse can give an attacker the same privileges as the user or process running the JRE, enabling further compromise.

Public detail is limited to the component and impact described above. Confirm exact affected builds, fixed releases, and any additional constraints directly against the vendor advisory before acting.

How it works

The flaw is an access control weakness in the Applet Rhino Script Engine portion of the Java Runtime Environment. In normal operation, applets and scripted content running inside the JRE are subject to the Java security manager and sandbox restrictions that limit what code may do on the host. This vulnerability undermines those controls.

An attacker who can deliver content that exercises the affected component—typically via a malicious or compromised web page that loads a Java applet—can bypass the intended restrictions and run code of their choosing in the context of the JRE process. The CWE is not specified in the available record, so treat it as a classic sandbox escape / improper access control issue in a client-side runtime. Do not assume particular exploit primitives, payloads, or reliability; those details are outside the provided facts and must be validated against the vendor advisory and your own threat intelligence.

Am I affected? How to find it in your systems

Oracle Java SE JDK and JRE installations are the in-scope products. They commonly appear on developer workstations, VDI images, legacy business applications that embed or call the JRE, and any browser or thick-client environment still configured to run Java applets.

Because exact version ranges are not supplied here, treat any unpatched Oracle Java SE JDK/JRE as potentially affected until you verify with the official advisory.

How to remediate

Patch first. Apply the updates Oracle published for this issue, following the vendor instructions referenced by CISA’s required action. Replace or upgrade every affected JDK and JRE instance, including those bundled inside third-party applications.

Retest critical applications after the update; some legacy software pins old JREs and may need vendor coordination or isolation.

If you can't patch immediately

Reduce exposure until the vendor update can be deployed:

These controls lower likelihood and impact but do not eliminate the vulnerability; schedule the official update as soon as practicable.

If your data may have been exposed

Actively exploited remote-code-execution flaws in client runtimes frequently lead to endpoint takeover and subsequent data theft or lateral movement. The available record does not document ransomware use for this CVE, yet any successful code execution should be treated as a potential breach until investigated. Review endpoint forensics, authentication logs, and data-access audits for the period the vulnerable JRE was exposed. As a quick additional check, users can run a free exposure scan of their email addresses against known breach datasets to see whether credentials or personal data have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · Java SE JDK and JRE
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities