CVE-2013-0431
KEV ransomwaremassSecurity Sandbox Bypass in Oracle Java Runtime Environment (JRE)
CISA: Oracle JRE Sandbox Bypass Vulnerability
CVE-2013-0431 is an unspecified vulnerability in the Oracle Java Runtime Environment (JRE) that allows remote attackers to bypass the Java security sandbox. It is triggered when a user running an affected, unpatched JRE loads attacker-supplied Java content, such as a malicious web applet delivered via a drive-by download (historically distributed via exploit kits, per related reporting on RedKit). Bypassing the sandbox lets the attacker escape Java's restricted execution environment, enabling arbitrary code execution on the victim system and follow-on malware or ransomware installation. Any system running a vulnerable version of Oracle JRE is affected, particularly desktops with the Java browser plugin enabled; the available data does not specify exact affected version ranges. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25) with known ransomware use and a 90% EPSS exploitation probability, indicating active in-the-wild exploitation; no public proof-of-concept is cataloged.
What to do: Upgrade the JRE to a release patched by Oracle per the vendor's Critical Patch Update instructions, as required by the CISA KEV listing. Where Java in the browser is not needed, disable or remove the Java browser plugin to reduce drive-by applet exposure. Check endpoints running older Java builds for signs of drive-by exploitation and ransomware precursor activity.
| Oracle Java Runtime Environment (JRE) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
- Affected
- Oracle Java Runtime Environment (JRE)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- Oracle
- Products
- Java Runtime Environment (JRE)