ZeroHour

CVE-2012-4681

KEV ransomwaremass

Remote Code Execution in Oracle Java SE Runtime Environment (JRE)

CISA: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVSS
EPSS
99%p100
Published
KEV added
AI analysis

A vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE allows arbitrary code execution remotely. It is triggered when the JRE processes attacker-controlled input, letting the attacker run arbitrary code in the context of the affected Java process. Any system running an affected Oracle Java SE build is exposed, including desktops and servers where Java is installed or used. Exploitation is confirmed in the wild: the flaw was weaponized by exploit kits in 2012 (e.g., the Whitehole Exploit Kit, whose use in the wild coincided with this CVE's coverage), was added to CISA's KEV on 2022-03-03 with known ransomware use, and EPSS currently assigns a 98.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in this data, but the flaw should be treated as actively exploited and urgent to patch.

What to do: Inventory all systems running Oracle Java SE and apply updates per vendor instructions, as CISA's required action specifies. Where immediate patching is not possible, disable or restrict the Java browser plug-in and limit Java execution to trusted sites, since the flaw was historically exploited via drive-by exploit kits. Given the KEV listing and 98.5% EPSS score, prioritize patching internet-exposed and ransomware-relevant systems.

Affected
Oracle Java SE (JRE component)
Estimated exposure
massOrder of hundreds of millions of installations/endpoints (well above 1M); precise current count unknown from this data — Java SE was historically near-ubiquitous on enterprise desktops and servers (Oracle long claimed billions of Java-enabled devices), and the flaw's CISA KEV listing with known ransomware use indicates substantial unpatched Java estates…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

CISA Known Exploited Vulnerability
Affected
Oracle Java SE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Oracle
Products
Java SE

In the news