Vulnerability record · CVE-2010-3552 · published 19 October 2010
CVE-2010-3552: Oracle Java New Plug-in unspecified remote code execution flaw
Sun · Jre
CVE-2010-3552 is an unspecified vulnerability in the New Java Plug-in component of Oracle Java SE and Java for Business 6 Update 21. The record gives no root cause, no affected method and no attack detail, only that remote attackers can impact confidentiality, integrity and availability via unknown vectors. Because the flaw sits in the browser plug-in and carries a maximum CVSS 2.0 score, it matters as a potential drive-by compromise path for any host running the affected JRE.
Description
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityMaximum CVSS 2.0 base score of 10 with network reachability and no authentication, combined with a very high EPSS percentile, makes this a top remediation item despite the thin technical detail.
What it is
CVE-2010-3552 is an unspecified vulnerability in the New Java Plug-in component of Oracle Java SE and Java for Business 6 Update 21. The record gives no root cause, no affected method and no attack detail, only that remote attackers can impact confidentiality, integrity and availability via unknown vectors. Because the flaw sits in the browser plug-in and carries a maximum CVSS 2.0 score, it matters as a potential drive-by compromise path for any host running the affected JRE.
Impact
An attacker who successfully exploits the flaw can affect confidentiality, integrity and availability, which at a CVSS 2.0 base score of 10 implies full compromise of the Java process and likely the underlying user session. The record does not specify whether code execution, sandbox escape or data disclosure is the actual outcome.
Attack surface
The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no special conditions. Given the New Java Plug-in component, the realistic path is a user visiting a malicious or compromised web page that loads a crafted Java applet, so user interaction (browsing) is effectively required even though the vector does not encode it.
Exploitation
The CVE is not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high at 0.8074 (99.6th percentile), indicating strong modeled likelihood of exploitation activity, but that is a statistical estimate, not evidence of a working exploit.
What to do
- Apply the Oracle October 2010 Critical Patch Update for Java SE and Java for Business, which is the vendor advisory and patch reference for this CVE.
- Apply the corresponding Red Hat, openSUSE, HP and Avaya vendor advisories for bundled or redistributed Java runtimes.
- Disable or remove the Java browser plug-in on systems that do not require it, and block applet execution in browsers.
- Where the plug-in must remain, restrict Java to an allowlist of trusted sites and keep the JRE at the latest supported release.
- Retire Java 6 Update 21 and any other end-of-life JRE builds from user endpoints.
Detection
- Inventory endpoints and servers for Java 6 Update 21 or earlier JRE/JDK builds and flag them for remediation.
- Monitor browser and proxy logs for applet (.class/.jar) downloads from untrusted or newly seen domains.
- Alert on java.exe or the browser plug-in spawning unexpected child processes such as cmd.exe, powershell.exe or script interpreters.
- Watch for JRE processes making outbound network connections to non-corporate destinations shortly after a browser session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3552 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.