cbcvebase.
CVE-2012-0507
published 2012-06-07

CVE-2012-0507: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33…

PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
98.11%
99.9th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
oraclejre
oraclejre
oraclevirtualization
sunjre
sunjre
suselinux_enterprise_desktop
suselinux_enterprise_java
suselinux_enterprise_java
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_software_development_kit

Detection & IOCsextracted from sources · hover to see the quote

domainbodyrocks.rr.nu
domainfemalebodyinspector.rr.nu
domainjohncartermovie2012.com
  • CVE-2012-0507 exploits the AtomicReferenceArray class by not ensuring the array is of Object[] type, enabling Java sandbox bypass; detect Java processes spawning unexpected child processes or writing executables to disk.
  • The exploit was bundled into the BlackHole exploit kit and RedKit exploit kit; monitor for drive-by-download traffic patterns associated with these kits delivering Java exploits targeting CVE-2012-0507.
  • RedKit EK initially included CVE-2012-0507 (Java AtomicReferenceArray) as one of its two original exploits; iframes on compromised websites performed simultaneous actions when rendered in a victim's browser.
  • Flashback.K variant exploits CVE-2012-0507 to infect Mac systems without requiring a password; monitor for Java processes on macOS spawning unexpected network connections or writing to LaunchAgents/LaunchDaemons.
  • Flashback Trojan sniffs network traffic for usernames and passwords and has web-inject capability to modify web pages viewed in Safari; monitor for suspicious browser process injection or unexpected Safari helper processes.
  • CVE-2012-0507 was used in strategic web compromise (watering-hole) attacks against foreign policy and human rights websites; monitor for Java exploit delivery from high-profile or niche-interest websites.
  • Successful exploitation of CVE-2012-0507 was observed dropping the ZeuS Trojan; monitor for ZeuS-related IOCs following Java exploitation events.
  • ·Patched versions not vulnerable: Java 6 Update 31 and Java 7 Update 3 (released Feb 15, 2012) fix CVE-2012-0507; Apple's patches were Java for OS X Lion 2012-001 and Java for Mac OS X 10.6 Update 7.
  • ·Patch adoption was extremely low (~10%) one month after release; approximately 60-80% of Java users remained vulnerable at the time of widespread exploitation.
  • ·Apple's patch lagged Oracle's by approximately six weeks, leaving Mac users exposed longer than Windows users.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_ubuntu6.4MEDIUM
vendor_redhat3.6LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.