Junglewise Threat Intelligence

CVE-2012-4681: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVE-2012-4681 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Oracle Java SE, Oracle JRockit. Vendors: Oracle.

Executive brief

Multiple vulnerabilities in the Oracle Java SE Runtime Environment (JRE) allow remote attackers to bypass SecurityManager restrictions and execute arbitrary code. The exploit involves using ClassFinder.findClass to access restricted classes and leveraging reflection to modify private fields via a crafted applet.

Affected products

  • Oracle Java SE 7 Update 6 and earlier 7 Update 6 and earlier

Timeline

  • 2012-08: exploited: Exploited in the wild using Gondzz.class and Gondvv.class.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats