ZeroHour

CVE-2013-0422

KEV ransomwaremass

Java Applet Permission-Restriction Flaw Enables Remote Code Execution in Oracle JRE

CISA: Oracle JRE Remote Code Execution Vulnerability

CVSS
EPSS
98%p100
Published
KEV added
AI analysis

CVE-2013-0422 is a flaw in how Oracle's Java Runtime Environment restricts the permissions of Java applets (CWE-264), allowing an applet to run with privileges beyond its intended security sandbox. It is triggered when a user loads a web page that delivers a malicious Java applet, such as via a drive-by visit or a phishing link pointing to an attacker-controlled site. Successful exploitation lets the attacker execute commands in the context of the current user on the client system, which in the 2013 campaigns was used to deliver malware families tracked in exploit kits and APT activity (e.g., Whitehole, Miniduke, Icefog) and is recorded by CISA as being used in ransomware. Any system with Oracle JRE installed—especially workstations and browsers with the Java applet plug-in enabled—is affected. Exploitation is confirmed in the wild: the flaw was mass-exploited by exploit kits at the time of disclosure, it carries a 97.6% EPSS probability of exploitation (100th percentile), and it was added to CISA KEV on 2022-05-25, so patching remains an active requirement.

What to do: Apply Oracle's Java updates per vendor instructions — at disclosure this meant the emergency Java 7 Update 11 or later, and today the current supported Java release. As interim mitigation, disable the Java browser plug-in (or Java in browsers) and uninstall JRE where it is no longer needed. Given known in-the-wild use by exploit kits and ransomware, prioritize KEV remediation and check endpoints for drive-by web-borne infections delivered via malicious applets.

Affected
Oracle Java Runtime Environment (JRE)
Estimated exposure
masshundreds of millions of Java installs (Java was near-ubiquitous on enterprise desktops and servers in 2013) — Based on 2013 public reporting and scans showing the Java browser plug-in and JRE present on a large share of enterprise and consumer endpoints, making the affected population an order-of-magnitude mass of installations rather than a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

CISA Known Exploited Vulnerability
Affected
Oracle Java Runtime Environment (JRE)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Oracle
Products
Java Runtime Environment (JRE)
Weakness
CWE-264

In the news