CVE-2016-0603 is an unspecified vulnerability in Oracle Java SE (versions 6u111, 7u95, 8u71, 8u72) running on Windows, potentially allowing remote attackers to compromise confidentiality, integrity, and availability through unknown vectors related to the Java installer. With a CVSS score of 7.6, this vulnerability has a high attack complexity but could lead to complete compromise of the system. While Oracle has not confirmed third-party claims of an untrusted search path issue enabling privilege escalation via a Trojan horse DLL, there is no evidence of active exploitation, and no public exploit code is available. Despite this, the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update111:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update95:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update71:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update72:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update111:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.