CVE-2012-4681
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
- Affected products
- Centos, Hp-Ux, Java Platform, Oracle Java Se, Red Hat, Suse
- Oracle Jdk
- = 1.6.0, 1.7.0
- Oracle Jre
- = 1.6.0, 1.7.0
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 98.5% (100th percentile)
- Weakness
- CWE-284
- NVD status
- Analyzed
- Published
- 2012-08-28
CVE-2012-4681 at NVD
12 known exploits for CVE-2012-4681
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2012-4681-Armoring
PoCs-CVE_2012_4681
exploits
Exploit for Improper Access Control in Oracle Jdk
Oracle Sun JRE 1.x 远程JRE漏洞
Oracle Java findMethod findClass Security Bypass
Oracle Java findMethod findClass Security Bypass
Oracle Java findMethod findClass Security Bypass
Oracle Java findMethod findClass Security Bypass
Immunity Canvas: JAVA_FORNAME_GETFIELD
Java 7 Applet - Remote Code Execution (Metasploit)
Java 7 Applet Remote Code Execution