Vulnerability record · CVE-2009-3869 · published 5 November 2009
CVE-2009-3869: Sun Java SE AWT setDiffICM Stack Buffer Overflow
Sun · Jdk
A stack-based buffer overflow exists in the setDiffICM function of the Abstract Window Toolkit (AWT) in Sun Java SE. A crafted argument can overflow a stack buffer, and because the affected component is reachable through Java content, the flaw can lead to arbitrary code execution. The issue affects multiple JDK/JRE/SDK release lines and was fixed in vendor updates.
Description
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with complete impact and has a very high EPSS percentile, though it is not listed in KEV and requires medium attack complexity.
What it is
A stack-based buffer overflow exists in the setDiffICM function of the Abstract Window Toolkit (AWT) in Sun Java SE. A crafted argument can overflow a stack buffer, and because the affected component is reachable through Java content, the flaw can lead to arbitrary code execution. The issue affects multiple JDK/JRE/SDK release lines and was fixed in vendor updates.
Impact
A remote attacker can execute arbitrary code in the context of the Java process, potentially leading to full compromise of the host running the vulnerable JRE. The CVSS 2.0 vector indicates complete confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is network-reachable (AV:N) with no authentication required (Au:N), but exploitation requires medium complexity (AC:M), consistent with a crafted argument being supplied to the setDiffICM function. User interaction is not explicitly stated in the record, but the AWT context suggests a Java application or applet path may be involved.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is high at 0.65461 (99.225th percentile), indicating a meaningful probability of exploitation activity. No ransomware group usage is documented.
What to do
- Apply the vendor patch by upgrading to JDK/JRE 5.0 Update 22 or later, JDK/JRE 6 Update 17 or later, SDK/JRE 1.3.1_27 or later, or SDK/JRE 1.4.2_24 or later as applicable.
- Disable or restrict Java applet and Web Start execution in browsers and clients where the vulnerable JRE cannot be immediately updated.
- Remove or isolate end-of-life Java 1.3.x, 1.4.x, 5.0, and 6 releases from production and user endpoints.
- Apply the referenced vendor advisories and distribution updates (for example, Red Hat, Apple, Gentoo, Mandriva, openSUSE) where the affected JRE is packaged.
- Monitor for and block untrusted Java content delivery paths until patching is complete.
Detection
- Inventory endpoints and servers for installed Java versions matching the affected release lines (JDK/JRE 5.0 before Update 22, JDK/JRE 6 before Update 17, SDK/JRE 1.3.x before 1.3.1_27, SDK/JRE 1.4.x before 1.4.2_24).
- Monitor for crashes or abnormal termination of java.exe/javaw processes that could indicate stack corruption attempts.
- Use application allowlisting or browser telemetry to detect unexpected Java applet or Web Start execution.
- Review proxy and endpoint logs for delivery of Java archives from untrusted or unusual sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3869 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3869), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.