ZeroHour

CVE-2012-1723

KEV ransomwaremass

Remote Arbitrary Code Execution in Oracle Java SE (Hotspot Component)

CISA: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVSS
EPSS
94%p100
Published
KEV added
AI analysis

Oracle Java SE's Java Runtime Environment contains an unspecified flaw in its Hotspot component that allows remote attackers to affect confidentiality, integrity, and availability — characterized by CISA as arbitrary code execution. The available data does not document the exact trigger beyond 'unknown vectors related to Hotspot,' but flaws in the JVM's execution engine of this type are typically reached remotely by having the runtime process malicious Java content. A successful attacker gains code execution in the context of the process running the JVM, taking control of the affected host. Any deployment running affected, unpatched Oracle Java SE — particularly legacy JRE installs — is affected. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use and a 93.7% EPSS probability of exploitation in the next 30 days, confirming active in-the-wild exploitation, though the reviewed data lists no public PoC.

What to do: Per CISA's required action, apply updates per vendor instructions: upgrade every Oracle Java SE installation to a currently supported patched release and inventory for legacy JRE builds that predate the 2012 Hotspot fix. Disable or restrict the Java browser plugin where it is not needed, and given known ransomware use, prioritize legacy Java systems for patching and threat-hunting.

Affected
Oracle Java SE (Java Runtime Environment, JRE)
Estimated exposure
mass≈ millions of endpoints running legacy, unpatched Java (exact count unknown) — Java is among the most widely deployed runtimes in enterprise and endpoint environments and legacy systems commonly retain old unpatched JRE builds, making a multi-million installation footprint plausible, though the source data provides…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.

CISA Known Exploited Vulnerability
Affected
Oracle Java SE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Oracle
Products
Java SE

In the news