CVE-2012-4681
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-284
מוצרים מושפעים
oracle: jdk; oracle: jre; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux server; redhat: enterprise linux workstation
קישורים
- http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.… Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.… Vendor Advisory
- http://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.… ExploitThird Party Advisory
- http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-… Broken LinkExploit
- http://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.… ExploitThird Party Advisory
- http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-… Broken LinkExploit
- http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html Mailing List
- http://marc.info/?l=bugtraq&m=135109152819176&w=2 Issue TrackingMailing ListThird Party Advisory