CVE-2012-1533
published 2012-10-16CVE-2012-1533: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote…
PriorityP276critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
68.53%
99.3th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-3159.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection"; flow:established,to_client; file.data; content:"<jnlp"; nocase; content:"initial-heap-size"; nocase; content:"max-heap-size"; content:"-XXaltjvm"; nocase; fast_pattern; reference:cve,2012-1533; classtype:trojan-activity; sid:2017013; rev:4; metadata:created_at 2013_06_13, cve CVE_2012_1533, confidence Medium, signature_severity Major, updated_at 2024_03_13, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
- →Detect malicious JNLP files containing both 'initial-heap-size' and 'max-heap-size' parameters alongside the '-XXaltjvm' option, which is the core injection vector for this CVE. ↗
- →Watch for javaws.exe or javaw.exe spawning processes or loading DLLs from UNC/WebDAV paths, which indicates successful -XXaltjvm injection from a remote share. ↗
- →The exploit requires the target to have the WebClient service (WebDAV Mini-Redirector) enabled; presence of WebDAV PROPFIND requests for .dll files from a Java process is a strong indicator of exploitation. ↗
- →The exploit serves the malicious JNLP on port 80 with URIPATH '/'; look for HTTP GET requests for .jnlp files followed by WebDAV PROPFIND/GET requests for .dll files from the same host as a kill-chain indicator. ↗
- ·The exploit only targets Windows x86 platforms (XP SP3 and Windows 7) and requires the attacker's server to run on port 80 with URIPATH '/' when using the WebDAV delivery method; non-Windows hosts are not affected by this specific attack chain. ↗
- ·Affected versions are strictly JRE 1.6.31 through 1.6.35 and 1.7.03 through 1.7.07; versions 1.6.37+ and 1.7.09+ (patched in October 2012) are not vulnerable. ↗
- ·An alternative UNCPATH can be specified to bypass the WebDAV/SMB limitation, allowing use of a pre-staged SMB server instead of the built-in WebDAV delivery. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-39xq-q2rq-4395: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allow
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2012-1533 [HIGH] GHSA-39xq-q2rq-4395: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allow
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-3159.
GHSA
GHSA-rm3j-xjw9-m9p3: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allow
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2012-3159 [CRITICAL] GHSA-rm3j-xjw9-m9p3: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allow
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-1533.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2012-10-26·CVSS 10.0
CVE-2012-1531 [CRITICAL] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Several information disclosure vulnerabilities were discovered in the
OpenJDK JRE. (CVE-2012-3216, CVE-2012-5069, CVE-2012-5072, CVE-2012-5075,
CVE-2012-5077, CVE-2012-5085)
Vulnerabilities were discovered in the OpenJDK JRE related to information
disclosure and data integrity. (CVE-2012-4416, CVE-2012-5071)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to cause a denial of service. (CVE-2012-1531, CVE-2012-1532, CVE-2012-1533,
CVE-2012-3143, CVE-2012-3159, CVE-2012-5068, CVE-2012-5083, CVE-2012-5084,
CVE-2012-5086, CVE-2012-5089)
Information disclosure vulnerabilities were discovered in the OpenJDK JR
Red Hat
JDK: unspecified vulnerability (Deployment)
vendor_redhat·2012-10-16·CVSS 10.0
CVE-2012-1533 [CRITICAL] JDK: unspecified vulnerability (Deployment)
JDK: unspecified vulnerability (Deployment)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-3159.
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Affected
Red Hat
JDK: unspecified vulnerability (Deployment)
vendor_redhat·2012-10-16·CVSS 10.0
CVE-2012-3159 [CRITICAL] JDK: unspecified vulnerability (Deployment)
JDK: unspecified vulnerability (Deployment)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-1533.
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Affected
Suricata
ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
suricata·2013-06-13
CVE-2012-1533 ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection"; flow:established,to_client; file.data; content:"<jnlp"; nocase; content:"initial-heap-size"; nocase; content:"max-heap-size"; content:"-XXaltjvm"; nocase; fast_pattern; reference:cve,2012-1533; classtype:trojan-activity; sid:2017013; rev:4; metadata:created_at 2013_06_13, cve CVE_2012_1533, confidence Medium, signature_severity Major, updated_at 2024_03_13, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
Exploit-DB
Java - Web Start Double Quote Injection Remote Code Execution (Metasploit)
exploitdb·2013-06-11
CVE-2012-1533 Java - Web Start Double Quote Injection Remote Code Execution (Metasploit)
Java - Web Start Double Quote Injection Remote Code Execution (Metasploit)
---
##
#
# ========================================================
# Java Web Start Double Quote Inject Remote Code Execution
# ========================================================
#
# Date: Jun 12 2012 (updated: Jun 6 2013)
# Author: Rh0
# Version: At least Java 1.6.31 to 1.6.35 and 1.7.03 to 1.7.07
# Tested on: Windows XP SP3 EN and Windows 7
# CVE: 2012-1533
#
# advisory: http://pastebin.com/eUucVage
#
##
require 'msf/core'
class Metasploit3 'Sun Java Web Start Double Quote Injection',
'Description' => %q{
This module exploits a flaw in the Web Start component of the Sun Java
Runtime Environment. Parameters intial-heap-size and max-heap-size in a JNLP
file can contain a double quote which is not properly
Metasploit
Sun Java Web Start Double Quote Injection
metasploit
Sun Java Web Start Double Quote Injection
Sun Java Web Start Double Quote Injection
This module exploits a flaw in the Web Start component of the Sun Java Runtime Environment. Parameters initial-heap-size and max-heap-size in a JNLP file can contain a double quote which is not properly sanitized when creating the command line for javaw.exe. This allows the injection of the -XXaltjvm option to load a jvm.dll from a remote UNC path into the java process. Thus an attacker can execute arbitrary code in the context of a browser user. This flaw was fixed in Oct. 2012 and affects JRE <= 1.6.35 and <= 1.7.07. In order for this module to work, it must be run as root on a server that does not serve SMB (In most cases, this means non-Windows hosts). Additionally, the target host must have the WebClient service (WebDAV Mini-Redirector) enabl
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00022.htmlhttp://marc.info/?l=bugtraq&m=135542848327757&w=2http://marc.info/?l=bugtraq&m=135758563611658&w=2http://rhn.redhat.com/errata/RHSA-2012-1391.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1392.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/51326http://secunia.com/advisories/51327http://secunia.com/advisories/51390http://secunia.com/advisories/51438http://www-01.ibm.com/support/docview.wss?uid=swg21616490http://www-01.ibm.com/support/docview.wss?uid=swg21620037http://www-01.ibm.com/support/docview.wss?uid=swg21621154http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.htmlhttp://www.securityfocus.com/bid/56046http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79416https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16648http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00022.htmlhttp://marc.info/?l=bugtraq&m=135542848327757&w=2http://marc.info/?l=bugtraq&m=135758563611658&w=2http://rhn.redhat.com/errata/RHSA-2012-1391.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1392.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/51326http://secunia.com/advisories/51327http://secunia.com/advisories/51390http://secunia.com/advisories/51438http://www-01.ibm.com/support/docview.wss?uid=swg21616490http://www-01.ibm.com/support/docview.wss?uid=swg21620037http://www-01.ibm.com/support/docview.wss?uid=swg21621154http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.htmlhttp://www.securityfocus.com/bid/56046http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79416https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16648
2012-10-16
Published