CVE-2013-2423
KEVmassRemote Integrity-Affecting Vulnerability in Oracle JRE HotSpot (CVE-2013-2423)
CISA: Oracle JRE Unspecified Vulnerability
An unspecified vulnerability in the HotSpot component of Oracle's Java Runtime Environment (JRE) can be triggered remotely, allowing attackers to affect the integrity of the affected system. Oracle did not publish technical detail for the flaw, so defenders should treat unpatched legacy JRE deployments as potentially exposed without being able to precisely scope the trigger. An attacker who successfully exploits it gains the ability to tamper with the target's integrity; related reporting around the LightsOut Exploit Kit and compromised websites suggests Java flaws of this era were used in drive-by web attacks. Any endpoint or server running an unpatched Oracle JRE is affected, with legacy Java installations that never received current updates being the most likely remaining targets. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, and EPSS assigns it an 85.3% probability of exploitation within 30 days (100th percentile), though no public proof-of-concept is catalogued and ransomware use is unknown.
What to do: Apply Oracle's Java updates immediately per CISA's required action: upgrade all JRE installations to a currently supported release, at minimum incorporating the April 2013 Oracle Critical Patch Update that addressed this flaw. Inventory endpoints and servers for legacy JRE installs, remove or disable the Java browser plugin where it is not required, and watch for drive-by exploit kit activity (e.g., LightsOut) as an indicator of exposure.
| Oracle Java Runtime Environment (JRE) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
- Affected
- Oracle Java Runtime Environment (JRE)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Oracle
- Products
- Java Runtime Environment (JRE)