CVE-2012-1723
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 93.69% probability · 100th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022 · used in ransomware campaigns
- Weakness
- CWE-284
- Affected
- oracle/jdk · oracle/jre · redhat/icedtea6 · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation
- Source
- secalert_us@oracle.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2012-1723
References
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlMailing List
- http://marc.info/?l=bugtraq&m=134496371727681&w=2Mailing List
- http://rhn.redhat.com/errata/RHSA-2012-0734.htmlThird Party Advisory
- http://secunia.com/advisories/51080Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21615246Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:095Broken Link
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlVendor Advisory
- http://www.securityfocus.com/bid/53960Broken Link, Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16259Broken Link
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlMailing List
- http://marc.info/?l=bugtraq&m=134496371727681&w=2Mailing List
- http://rhn.redhat.com/errata/RHSA-2012-0734.htmlThird Party Advisory
- http://secunia.com/advisories/51080Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21615246Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:095Broken Link
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlVendor Advisory
- http://www.securityfocus.com/bid/53960Broken Link, Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16259Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1723US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.