CVE-2013-2460

EXPLOITED

Oracle Java SE <7 Update 21 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-2460 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Metasploit, Adam Gowdiak, s advisory and also POC, including a Metasploit module exploits/multi/browser/java_jre17_provider_skeleton.

AI-analyzed exploit summary This Metasploit module exploits CVE-2013-2460 by abusing the insecure invoke() method of the ProviderSkeleton class in Java 7u21 and earlier, allowing arbitrary static method calls with user-supplied arguments. It delivers a malicious JAR file via an HTML page with an applet tag, achieving remote code execution.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "insufficient access checks" in the tracing component.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/26529

This Metasploit module exploits CVE-2013-2460 by abusing the insecure invoke() method of the ProviderSkeleton class in Java 7u21 and earlier, allowing arbitrary static method calls with user-supplied arguments. It delivers a malicious JAR file via an HTML page with an applet tag, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) 7u21 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java applet must be allowed to run
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC GREAT
by Adam Gowdiak, s advisory and also POC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_jre17_provider_skeleton.rb

This Metasploit module exploits CVE-2013-2460, targeting Java 7u21 and earlier by abusing the insecure invoke() method of the ProviderSkeleton class to achieve arbitrary static method execution. It delivers a malicious JAR file via an HTML page with an embedded applet.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment (JRE) 7u21 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java applet must be allowed to run
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (16)

Core 16
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1060.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-32.xml
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=137545505800971&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/54154
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19129
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17116
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/ncas/alerts/TA13-169A
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2013-0185.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=975122
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0963.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21642336

Scores

EPSS 0.8452
EPSS Percentile 99.4%

Details

VulnCheck KEV 2021-08-17
Status published
Products (4)
oracle/jdk 1.7.0 (14 CPE variants)
oracle/jdk < 1.7.0
oracle/jre 1.7.0 (14 CPE variants)
oracle/jre < 1.7.0
Published Jun 18, 2013
Tracked Since Feb 18, 2026