CVE-2012-4681
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.54% probability · 100th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022 · used in ransomware campaigns
- Weakness
- CWE-284
- Affected
- oracle/jdk · oracle/jre · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2012-4681
References
- http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.htmlThird Party Advisory
- http://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.htmlExploit, Third Party Advisory
- http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/Broken Link, Exploit
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlMailing List
- http://marc.info/?l=bugtraq&m=135109152819176&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1225.htmlThird Party Advisory
- http://secunia.com/advisories/51044Not Applicable
- http://www.deependresearch.org/2012/08/java-7-vulnerability-analysis.htmlBroken Link, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.htmlVendor Advisory
- http://www.securityfocus.com/bid/55213Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA12-240A.htmlThird Party Advisory, US Government Resource
- https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0dayBroken Link, Third Party Advisory
- http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.htmlThird Party Advisory
- http://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.htmlExploit, Third Party Advisory
- http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/Broken Link, Exploit
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlMailing List
- http://marc.info/?l=bugtraq&m=135109152819176&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1225.htmlThird Party Advisory
- http://secunia.com/advisories/51044Not Applicable
- http://www.deependresearch.org/2012/08/java-7-vulnerability-analysis.htmlBroken Link, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.htmlVendor Advisory
- http://www.securityfocus.com/bid/55213Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA12-240A.htmlThird Party Advisory, US Government Resource
- https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0dayBroken Link, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-4681US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.