CVE-2008-5353

EXPLOITED

Sun Java Calendar Deserialization Privilege Escalation

Title source: metasploit

Description

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16302
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16293
exploitdb WRITEUP VERIFIED
by Landon Fuller · textremoteosx
https://www.exploit-db.com/exploits/8753
exploitdb WORKING POC VERIFIED
by sf · rubyremotemultiple
https://www.exploit-db.com/exploits/9948
metasploit WORKING POC EXCELLENT
by sf, hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_calendar_deserialize.rb

References (42)

... and 22 more

Scores

EPSS 0.8953
EPSS Percentile 99.6%

Details

VulnCheck KEV 2010-01-05
Status published
Products (22)
sun/jdk 5.0 update_1 (15 CPE variants)
sun/jdk 6 (10 CPE variants)
sun/jdk < 5.0
sun/jdk < 6
sun/jre 1.4.2_1
sun/jre 1.4.2_2
sun/jre 1.4.2_3
sun/jre 1.4.2_4
sun/jre 1.4.2_5
sun/jre 1.4.2_6
... and 12 more
Published Dec 05, 2008
Tracked Since Feb 18, 2026