CVE-2012-4681
KEV ransomwaremassRemote Code Execution in Oracle Java SE Runtime Environment (JRE)
CISA: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
A vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE allows arbitrary code execution remotely. It is triggered when the JRE processes attacker-controlled input, letting the attacker run arbitrary code in the context of the affected Java process. Any system running an affected Oracle Java SE build is exposed, including desktops and servers where Java is installed or used. Exploitation is confirmed in the wild: the flaw was weaponized by exploit kits in 2012 (e.g., the Whitehole Exploit Kit, whose use in the wild coincided with this CVE's coverage), was added to CISA's KEV on 2022-03-03 with known ransomware use, and EPSS currently assigns a 98.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in this data, but the flaw should be treated as actively exploited and urgent to patch.
What to do: Inventory all systems running Oracle Java SE and apply updates per vendor instructions, as CISA's required action specifies. Where immediate patching is not possible, disable or restrict the Java browser plug-in and limit Java execution to trusted sites, since the flaw was historically exploited via drive-by exploit kits. Given the KEV listing and 98.5% EPSS score, prioritize patching internet-exposed and ransomware-relevant systems.
| Oracle Java SE (JRE component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.
- Affected
- Oracle Java SE
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- Oracle
- Products
- Java SE