Oracle investigating after two more Java 7 zero-day flaws found
Summary: Polish security researchers have discovered yet more zero-day vulnerabilities in Java, the beleaguered Web plug-in, that led to the successful intrusion of Facebook, Apple and Microsoft in recent weeks. — Zack Whittaker
Context & Ripple Effects
Oracle had already raised Java applet security in its January Java 7 Update 11 security update and accelerated Update 13 after an exploited flaw. The discovery of two further zero-days undercuts the reassurance those releases were meant to provide.
The stakes extend beyond a routine software defect: the article ties earlier Java zero-days to successful intrusions at Facebook, Apple and Microsoft, while an earlier exploit had already shown potential exposure for Macs.
First-order effects
- Oracle must investigate two newly identified Java 7 flaws while users remain exposed to vulnerabilities without a disclosed fix.
- Facebook, Apple and Microsoft have added reason to treat Java as an active intrusion route after the earlier compromises linked to Java zero-days.
Second-order effects
- The new findings weaken the security assurance of Oracle's January update cycle, pushing enterprise Java users to reassess whether patched releases and stricter applet settings sufficiently reduce exposure.
- Java-dependent organizations face greater pressure to restrict browser-plugin use, shifting the operational burden from Oracle's patch releases to local deployment controls.
Third-order effects
- A continuing sequence of exploited flaws, accelerated fixes and newly found zero-days points toward browser plug-ins being managed as a persistent enterprise attack surface rather than a component secured by periodic updates.
- If Java's update cadence continues to be overtaken by vulnerability discovery, trust in the plug-in model will depend increasingly on organizations limiting where and how it runs.
The trend: Enterprise security is moving from patch-centric trust in browser plug-ins toward tighter control of software that repeatedly becomes an intrusion path.