CVE-2017-3241PoC(oracle / jdk)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for oracle jdk systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS v3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jdk
  • jre
  • jrockit

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
jdkjrejrockit

4 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-15: 1Exploit Tool / Code · 2026-05-15: 1Technical Details · 2026-05-15: 105-15
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Israel@f1tym1
    PoC

    CVE-2017-3241 | Oracle Java SE 6u131/7u121/8u112 RMI ObjectInputStream.skipCustomData input validation (EDB-41145 / Nessus ID 96628) https://ift.tt/9teLX4K A vulnerability was found in Oracle Java SE 6u131/7u121/8u112 and classified as critical. This affects the function Objec…

    Post summary

    A critical vulnerability (CVE-2017-3241) in Oracle Java SE is mentioned, with a reference to an EDB PoC and Nessus ID, but no evidence of active exploitation or patch information.

    0000030
    974 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclejdk1.6--
Apporaclejdk1.7--
Apporaclejdk1.8--
Apporaclejdk1.8--
Apporaclejre1.6--
Apporaclejre1.7--
Apporaclejre1.8--
Apporaclejre1.8--
Apporaclejrockitr28.3.12--

Explore more