CVE-2010-0840

CRITICAL KEV RANSOMWARE

Oracle Java SE/Jav for Bus <6-5.0-1.4.2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2010-0840 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 25, 2022, with confirmed use in ransomware campaigns. EIP tracks 2 public exploits from researchers including Metasploit, Sami Koivu, Matthias Kaiser, egypt, including a Metasploit module exploits/multi/browser/java_trusted_chain.

AI-analyzed exploit summary This Metasploit module exploits CVE-2010-0840, a Java trusted method chaining vulnerability, by delivering a malicious JAR file via an HTML page with an embedded applet. It achieves remote code execution by leveraging untrusted methods running in a privileged context in JRE versions prior to 6u19 and 5u23.

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16297

This Metasploit module exploits CVE-2010-0840, a Java trusted method chaining vulnerability, by delivering a malicious JAR file via an HTML page with an embedded applet. It achieves remote code execution by leveraging untrusted methods running in a privileged context in JRE versions prior to 6u19 and 5u23.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) 6 prior to update 19, JRE 5 prior to update 23
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java applet support must be enabled in the victim's browser
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Sami Koivu, Matthias Kaiser, egypt · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_trusted_chain.rb

This Metasploit module exploits CVE-2010-0840, a Java privilege escalation vulnerability in JRE versions 6 prior to update 19 and 5 prior to update 23. It uses a trusted method chain via Statement.invoke() to execute arbitrary code in a privileged context.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) 6 < Update 19, JRE 5 < Update 23
No auth needed
Prerequisites: Target must visit a malicious webpage hosting the exploit · Java applet must be allowed to run
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (41)

Core 41
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134254866602253&w=2
Broken Link, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/510528/100/0/threaded
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39317
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0383.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40545
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1454
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39819
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1107
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0338.html
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1793
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43308
Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
Broken Link vendor-advisory x_refsource_hp
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=127557596201693&w=2
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0339.html
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39292
Release Notes, Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT4170
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1523
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39065
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39659
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0471.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-923-1
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0337.html
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0489.html
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-10-056
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40211
Release Notes, Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT4171
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:084
Broken Link, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1191

Scores

CVSS v3 9.8
EPSS 0.9214
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-05-25
VulnCheck KEV 2011-07-26
InTheWild.io 2017-05-27
ENISA EUVD EUVD-2010-0865
Ransomware Use Confirmed
Status published
Products (10)
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
canonical/ubuntu_linux 9.04
canonical/ubuntu_linux 9.10
opensuse/opensuse 11.0
opensuse/opensuse 11.1
opensuse/opensuse 11.2
oracle/jre 1.4.2_25
oracle/jre 1.5.0 update23
oracle/jre 1.6.0 update18
Published Apr 01, 2010
KEV Added May 25, 2022
Tracked Since Feb 18, 2026