CVE-2013-0431
MEDIUM KEV RANSOMWAREOracle JRE 7 through Update 11 and OpenJDK 7 - Security Sandbox Bypass via JMX
Title source: llmExploitation Summary
CVE-2013-0431 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 25, 2022, with confirmed use in ransomware campaigns.
EIP tracks 2 public exploits from researchers including Metasploit, Unknown, Adam Gowdiak, SecurityObscurity, juan vazquez, including a Metasploit module exploits/multi/browser/java_jre17_jmxbean_2.
AI-analyzed exploit summary This Metasploit module exploits CVE-2013-0431, a Java Applet JMX vulnerability, to achieve remote code execution by bypassing Java 7 Update 10 security restrictions. It delivers a malicious JAR file via an HTML page, targeting multiple platforms (Java, Windows, macOS, Linux).
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
Exploits (2)
This Metasploit module exploits CVE-2013-0431, a Java Applet JMX vulnerability, to achieve remote code execution by bypassing Java 7 Update 10 security restrictions. It delivers a malicious JAR file via an HTML page, targeting multiple platforms (Java, Windows, macOS, Linux).
This Metasploit module exploits CVE-2013-0431, a vulnerability in Java JMX classes, to achieve remote code execution by bypassing sandbox restrictions and default security settings in Java 7 Update 10. It delivers a malicious JAR file via an HTML page to execute arbitrary Java code.
References (20)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N