CVE-2013-0431

MEDIUM KEV RANSOMWARE

Oracle JRE 7 through Update 11 and OpenJDK 7 - Security Sandbox Bypass via JMX

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-0431 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 25, 2022, with confirmed use in ransomware campaigns. EIP tracks 2 public exploits from researchers including Metasploit, Unknown, Adam Gowdiak, SecurityObscurity, juan vazquez, including a Metasploit module exploits/multi/browser/java_jre17_jmxbean_2.

AI-analyzed exploit summary This Metasploit module exploits CVE-2013-0431, a Java Applet JMX vulnerability, to achieve remote code execution by bypassing Java 7 Update 10 security restrictions. It delivers a malicious JAR file via an HTML page, targeting multiple platforms (Java, Windows, macOS, Linux).

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/24539

This Metasploit module exploits CVE-2013-0431, a Java Applet JMX vulnerability, to achieve remote code execution by bypassing Java 7 Update 10 security restrictions. It delivers a malicious JAR file via an HTML page, targeting multiple platforms (Java, Windows, macOS, Linux).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) 7 Update 10 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java Applet support enabled in the browser
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Unknown, Adam Gowdiak, SecurityObscurity, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_jre17_jmxbean_2.rb

This Metasploit module exploits CVE-2013-0431, a vulnerability in Java JMX classes, to achieve remote code execution by bypassing sandbox restrictions and default security settings in Java 7 Update 10. It delivers a malicious JAR file via an HTML page to execute arbitrary Java code.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) 1.7 Update 10 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java Applet support enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (20)

Core 20
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-32.xml
Not Applicable vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA13-032A.html
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jan/142
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/858729
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0237.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=136439120408139&w=2
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0247.html
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jan/195
Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=136733161405818&w=2
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/525387/30/0/threaded
Third Party Advisory x_refsource_confirm
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056

Scores

CVSS v3 5.3
EPSS 0.9154
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2022-05-25
VulnCheck KEV 2013-03-14
InTheWild.io 2013-02-20
ENISA EUVD EUVD-2013-0442
Ransomware Use Confirmed
CWE
CWE-693
Status published
Products (2)
oracle/jre 1.7.0 (11 CPE variants)
oracle/openjdk 7
Published Jan 31, 2013
KEV Added May 25, 2022
Tracked Since Feb 18, 2026