CVE-2008-5353
EXPLOITEDSun Java Calendar Deserialization Privilege Escalation
Title source: metasploitDescription
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16302
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16293
exploitdb
WRITEUP
VERIFIED
by Landon Fuller · textremoteosx
https://www.exploit-db.com/exploits/8753
metasploit
WORKING POC
EXCELLENT
by sf, hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_calendar_deserialize.rb
References (42)
... and 22 more
Scores
EPSS
0.8953
EPSS Percentile
99.6%
Details
VulnCheck KEV
2010-01-05
Status
published
Products (22)
sun/jdk
5.0 update_1 (15 CPE variants)
sun/jdk
6 (10 CPE variants)
sun/jdk
< 5.0
sun/jdk
< 6
sun/jre
1.4.2_1
sun/jre
1.4.2_2
sun/jre
1.4.2_3
sun/jre
1.4.2_4
sun/jre
1.4.2_5
sun/jre
1.4.2_6
... and 12 more
Published
Dec 05, 2008
Tracked Since
Feb 18, 2026