CVE-2012-0507

CRITICAL KEV RANSOMWARE

Java AtomicReferenceArray Type Violation Vulnerability

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2012-0507 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 3, 2022, with confirmed use in ransomware campaigns. EIP tracks 2 public exploits from researchers including Metasploit, Jeroen Frijters, sinn3r, juan vazquez, egypt, including a Metasploit module exploits/multi/browser/java_atomicreferencearray.

AI-analyzed exploit summary This Metasploit module exploits a type safety violation in Java's AtomicReferenceArray class (CVE-2012-0507) to escape the JRE sandbox and execute arbitrary payloads. It supports multiple platforms and payload types, including Java and native executables.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/18679

This Metasploit module exploits a type safety violation in Java's AtomicReferenceArray class (CVE-2012-0507) to escape the JRE sandbox and execute arbitrary payloads. It supports multiple platforms and payload types, including Java and native executables.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) versions prior to the fix for CVE-2012-0507
No auth needed
Prerequisites: Victim must visit a malicious webpage or open a crafted JAR file · Java applet support must be enabled in the victim's browser
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Jeroen Frijters, sinn3r, juan vazquez, egypt · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_atomicreferencearray.rb

This Metasploit module exploits a type safety violation in Java's AtomicReferenceArray class (CVE-2012-0507) to escape the JRE sandbox and execute arbitrary payloads. It supports multiple platforms and payload types, including reverse shells and native executables.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) versions prior to the fix for CVE-2012-0507
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java applet support must be enabled in the victim's browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (23)

Core 23
Core References
Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=133847939902305&w=2
Broken Link, Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48692
Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134254866602253&w=2
Broken Link, Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48589
Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=133365109612558&w=2
Issue Tracking, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1455.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.html
Broken Link, Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48950
Broken Link, Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48948
Broken Link, Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48915
Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=133364885411663&w=2
Mailing List, Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2420
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0508.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=788994
Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134254957702612&w=2
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0514.html
Broken Link, Exploit, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52161

Scores

CVSS v3 9.8
EPSS 0.9365
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-03
VulnCheck KEV 2012-07-02
InTheWild.io 2022-03-03
ENISA EUVD EUVD-2012-0539
Ransomware Use Confirmed
CWE
CWE-843
Status published
Products (6)
debian/debian_linux 6.0
debian/debian_linux 7.0
oracle/jre 1.6.0 update22 (8 CPE variants)
oracle/jre 1.7.0 (3 CPE variants)
sun/jre 1.5.0 (32 CPE variants)
sun/jre 1.6.0 (5 CPE variants)
Published Jun 07, 2012
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026