CVE-2018-2641 is a difficult-to-exploit vulnerability in the AWT subcomponent of Oracle Java SE and Java SE Embedded, affecting versions 6u171, 7u161, 8u152, 9.0.1, and 8u151 respectively. This vulnerability primarily impacts client-side Java deployments running untrusted code, such as sandboxed Java Web Start applications or applets. Successful attacks require user interaction and can lead to unauthorized modification or deletion of critical data accessible by Java SE/Embedded. The vulnerability has a CVSS 3.0 Base Score of 6.1 (Medium), indicating a network attack vector with high attack complexity and requiring user interaction. While there is no confidentiality or availability impact, successful exploitation can result in significant integrity compromise. Currently, there is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update171:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update161:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update152:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:9.0.1:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update171:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.