CVE-2008-5353 is a critical deserialization vulnerability affecting Sun JDK, JRE, and SDK versions 6 Update 10 and earlier, 5.0 Update 16 and earlier, and 1.4.2_18 and earlier. This flaw allows remote attackers to execute untrusted applets and applications with elevated privileges by manipulating ZoneInfo objects during deserialization, as demonstrated with Calendar objects. With a CVSS score of 10.0 and an EPSS score indicating high exploitability, this vulnerability poses a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Multiple Metasploit modules and ExploitDB entries confirm readily available exploit code, and while not explicitly listed as a KEV, its high community discussion and media coverage, including its association with the Flashback Trojan, suggest significant historical exploitation and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:*:update_16:*:*:*:*:*:* | ||
<= 6CPE matchmatch criteria | cpe:2.3:a:sun:jdk:*:update_10:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:5.0:update_1:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:5.0:update_11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.