Executive brief
Multiple vulnerabilities in the Oracle Java SE Runtime Environment (JRE) allow remote attackers to bypass SecurityManager restrictions and execute arbitrary code. The exploit involves using ClassFinder.findClass to access restricted classes and leveraging reflection to modify private fields via a crafted applet.
Affected products
- Oracle Java SE 7 Update 6 and earlier 7 Update 6 and earlier
Timeline
- 2012-08: exploited: Exploited in the wild using Gondzz.class and Gondvv.class.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.