CVE-2012-4681
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
CVSS
9.8
Crítico
EPSS
98.5%
p100
KEV
SÍ
3 mar 2022
Exploit Today
80
0-100
Publicado: 28 ago 2012 · Última mod.: 6 ago 2026 · CWE-284
Producto
Oracle / Java SE
Vulnerabilidad
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Añadido a KEV
3 mar 2022
Remediar antes de
24 mar 2022
Uso conocido en ransomware
Sí
Descripción resumida
The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.
Acción requerida
Apply updates per vendor instructions.
Notas
https://nvd.nist.gov/vuln/detail/CVE-2012-4681
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
- blog.fireeye.comhttp://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html
- immunityproducts.blogspot.comhttp://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.html
- labs.alienvault.comhttp://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html
- marc.infohttp://marc.info/?l=bugtraq&m=135109152819176&w=2
- rhn.redhat.comhttp://rhn.redhat.com/errata/RHSA-2012-1225.html
- secunia.comhttp://secunia.com/advisories/51044
- www.deependresearch.orghttp://www.deependresearch.org/2012/08/java-7-vulnerability-analysis.html
- www.oracle.comhttp://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html
- www.securityfocus.comhttp://www.securityfocus.com/bid/55213
- www.us-cert.govhttp://www.us-cert.gov/cas/techalerts/TA12-240A.html
- community.rapid7.comhttps://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day
- blog.fireeye.comhttp://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html
- immunityproducts.blogspot.comhttp://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.html
- labs.alienvault.comhttp://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html
- marc.infohttp://marc.info/?l=bugtraq&m=135109152819176&w=2
- rhn.redhat.comhttp://rhn.redhat.com/errata/RHSA-2012-1225.html