CVE-2012-0507
CRITICAL KEV RANSOMWAREJava AtomicReferenceArray Type Violation Vulnerability
Title source: metasploitExploitation Summary
CVE-2012-0507 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 3, 2022, with confirmed use in ransomware campaigns.
EIP tracks 2 public exploits from researchers including Metasploit, Jeroen Frijters, sinn3r, juan vazquez, egypt, including a Metasploit module exploits/multi/browser/java_atomicreferencearray.
AI-analyzed exploit summary This Metasploit module exploits a type safety violation in Java's AtomicReferenceArray class (CVE-2012-0507) to escape the JRE sandbox and execute arbitrary payloads. It supports multiple platforms and payload types, including Java and native executables.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Exploits (2)
This Metasploit module exploits a type safety violation in Java's AtomicReferenceArray class (CVE-2012-0507) to escape the JRE sandbox and execute arbitrary payloads. It supports multiple platforms and payload types, including Java and native executables.
This Metasploit module exploits a type safety violation in Java's AtomicReferenceArray class (CVE-2012-0507) to escape the JRE sandbox and execute arbitrary payloads. It supports multiple platforms and payload types, including reverse shells and native executables.
References (23)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H