cbcvebase.
CVE-2012-0500
published 2012-02-15

CVE-2012-0500: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2…

PriorityP272critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
58.97%
99.0th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

Affected

12 ranges
VendorProductVersion rangeFixed in
oraclejavafx<= 2.0.2
oraclejavafx
oraclejavafx
oraclejavafx
oraclejavafx
oraclejavafx
oraclejavafx
oraclejre<= 1.6.0
oraclejre<= 1.7.0
oraclejre
oraclejre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

command-XXaltjvm
filenamejvm.dll
otherapplication/x-java-jnlp-file
  • Detect JNLP files served over HTTP containing injected double-quote characters in java-vm-args, initial-heap-size, or max-heap-size parameters, which are used to inject -XXaltjvm pointing to a remote UNC/WebDAV path.
  • Monitor for WebDAV (WebClient / MiniRedir) requests to port 80 serving .dll files with Content-Type application/octet-stream, indicative of the -XXaltjvm DLL delivery stage.
  • Detect HTTP responses with Content-Type: application/x-java-jnlp-file that contain double-quote characters inside attribute values of java-vm-args or heap-size parameters.
  • Flag User-Agent strings matching Windows NT 5/6 or MiniRedir patterns combined with PROPFIND and OPTIONS HTTP methods on port 80, consistent with the WebDAV mini-redirector DLL retrieval phase of this exploit.
  • ·The Metasploit module requires SRVPORT=80 and URIPATH=/ to function; the WebDAV delivery mechanism will not work on non-standard ports.
  • ·Exploitation requires the WebClient service (WebDAV Mini-Redirector) to be enabled on the target Windows host; systems without this service are not exploitable via this vector.
  • ·The exploit targets Windows x86 platforms running Java Runtime on Windows; non-Windows or 64-bit targets are not covered by the known public module.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.