ZeroHour

CVE-2013-2423

KEVmass

Remote Integrity-Affecting Vulnerability in Oracle JRE HotSpot (CVE-2013-2423)

CISA: Oracle JRE Unspecified Vulnerability

CVSS
EPSS
85%p100
Published
KEV added
AI analysis

An unspecified vulnerability in the HotSpot component of Oracle's Java Runtime Environment (JRE) can be triggered remotely, allowing attackers to affect the integrity of the affected system. Oracle did not publish technical detail for the flaw, so defenders should treat unpatched legacy JRE deployments as potentially exposed without being able to precisely scope the trigger. An attacker who successfully exploits it gains the ability to tamper with the target's integrity; related reporting around the LightsOut Exploit Kit and compromised websites suggests Java flaws of this era were used in drive-by web attacks. Any endpoint or server running an unpatched Oracle JRE is affected, with legacy Java installations that never received current updates being the most likely remaining targets. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, and EPSS assigns it an 85.3% probability of exploitation within 30 days (100th percentile), though no public proof-of-concept is catalogued and ransomware use is unknown.

What to do: Apply Oracle's Java updates immediately per CISA's required action: upgrade all JRE installations to a currently supported release, at minimum incorporating the April 2013 Oracle Critical Patch Update that addressed this flaw. Inventory endpoints and servers for legacy JRE installs, remove or disable the Java browser plugin where it is not required, and watch for drive-by exploit kit activity (e.g., LightsOut) as an indicator of exposure.

Affected
Oracle Java Runtime Environment (JRE)
Estimated exposure
masshundreds of millions of endpoints (Java's historical install base), of which the remaining unpatched legacy subset is likely tens of thousands to millions of… — Java was historically deployed on a majority of enterprise desktops and servers and many internet-exposed JVM-based services, so the plausible installed base is far above one million systems, while the exploited-in-the-wild subset today is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.

CISA Known Exploited Vulnerability
Affected
Oracle Java Runtime Environment (JRE)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Oracle
Products
Java Runtime Environment (JRE)

In the news