CVE-2012-1723

CRITICAL KEV RANSOMWARE

Java Applet Field Bytecode Verifier Cache Remote Code Execution

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2012-1723 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 3, 2022, with confirmed use in ransomware campaigns. EIP tracks 3 public exploits from researchers including Metasploit, EthanNJC, Stefan Cornelius, mihi, littlelightlittlefire, juan vazquez, sinn3r, including a Metasploit module exploits/multi/browser/java_verifier_field_access.

AI-analyzed exploit summary This Metasploit module exploits a vulnerability in the HotSpot bytecode verifier (CVE-2012-1723) to escape the JRE sandbox and execute arbitrary code. It delivers a malicious Java applet via an HTTP server to achieve remote code execution.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotejava
https://www.exploit-db.com/exploits/19717

This Metasploit module exploits a vulnerability in the HotSpot bytecode verifier (CVE-2012-1723) to escape the JRE sandbox and execute arbitrary code. It delivers a malicious Java applet via an HTTP server to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle Java Runtime Environment (JRE) 7 Update 4 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java applet must be executed in a vulnerable JRE
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by EthanNJC · client-side
https://github.com/EthanNJC/CVE-2012-1723

This PoC exploits CVE-2012-1723, a Java Applet sandbox escape vulnerability, by manipulating ClassLoader references to bypass security restrictions and execute arbitrary commands. The exploit chain involves confusing the ClassLoader, defining a malicious class with elevated permissions, and executing a payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) 7 Update 4 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit applet · Java Applet support must be enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Stefan Cornelius, mihi, littlelightlittlefire, juan vazquez, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_verifier_field_access.rb

This Metasploit module exploits a vulnerability in the HotSpot bytecode verifier (CVE-2012-1723) to escape the JRE sandbox and execute arbitrary code. It uses a malicious Java applet to deliver a payload, supporting multiple platforms and architectures.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle Java Runtime Environment (JRE) 7 Update 4 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java applet must be executed in a vulnerable JRE
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-32.xml
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0734.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134496371727681&w=2
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53960
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:095
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51080

Scores

CVSS v3 9.8
EPSS 0.9408
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-03
VulnCheck KEV 2013-03-14
InTheWild.io 2022-03-03
ENISA EUVD EUVD-2012-1733
Ransomware Use Confirmed
CWE
CWE-284
Status published
Products (2)
oracle/jdk 1.5.0 (30 CPE variants)
oracle/jdk 1.6.0 (20 CPE variants)
Published Jun 16, 2012
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026