Sploitus

CVE-2012-4681

12 known exploits for CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

Oracle Jdk
= 1.6.0, 1.7.0
Oracle Jre
= 1.6.0, 1.7.0
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
98.5% (100th percentile)
Weakness
CWE-284
NVD status
Analyzed
Published
2012-08-28
CVE-2012-4681 at NVD
Authoritative description, scoring and affected products

12 known exploits for CVE-2012-4681

Proof-of-concept code and exploit modules indexed by Sploitus