ZeroHour

CVE-2013-2465

KEV ransomwaremass

Unspecified Flaw in Oracle Java SE 2D Component Exploited in the Wild (CVE-2013-2465)

CISA: Oracle Java SE Unspecified Vulnerability

CVSS
EPSS
99%p100
Published
KEV added
AI analysis

CVE-2013-2465 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE, located in the 2D graphics/rendering subsystem. It is triggered via unknown vectors related to 2D, typically when a hostile applet or application causes the JRE to process crafted graphical content. An attacker who successfully exploits it can affect confidentiality, integrity, and availability, which in practice means remote compromise of the affected system without user credentials. Any deployment of Oracle Java SE — end-user desktops with the browser plugin and servers running JRE releases current at the time of the June 2013 Oracle Critical Patch Update — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, EPSS assigns it a 98.7% probability of exploitation within 30 days (top percentile), and related 2013-era reporting around exploit kits such as LightsOut documents the era's heavy exploit-kit targeting of Java.

What to do: Apply the June 2013 Oracle Java SE Critical Patch Update, or any later supported Java SE release, per vendor instructions as CISA requires. Audit environments for legacy JRE installs and enabled Java browser plugin/applet support — especially on user-facing and internet-exposed legacy servers — and remove or upgrade them. Because CISA lists known ransomware use, prioritize patching external-facing and end-user systems.

Affected
Oracle Java SE (Java Runtime Environment)
Estimated exposure
masshundreds of millions of endpoints at the time of 2013 disclosure; today, a residual population of legacy Java deployments of unknown size — The JRE was near-ubiquitous on enterprise and consumer desktops in 2013 and remains pinned inside many legacy server applications, so order-of-magnitude exposure is mass-scale even though no source-provided install counts exist.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D

CISA Known Exploited Vulnerability
Affected
Oracle Java SE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Oracle
Products
Java SE

In the news