cbcvebase.
CVE-2012-1723
published 2012-06-16

CVE-2012-1723: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
93.69%
99.8th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

Affected

18 ranges
VendorProductVersion rangeFixed in
oraclejdk<= 1.4.2_37
oraclejdk
oraclejdk
oraclejdk
oraclejre<= 1.4.2_37
oraclejre
oraclejre
oraclejre
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhaticedtea6< 1.10.81.10.8
redhaticedtea6>= 1.11.0 < 1.11.31.11.3

Detection & IOCsextracted from sources · hover to see the quote

hashC35A5AA55C911F1F1CFF733E0F422C0DE316CFFAF3B285ABA57A4CFDB7188341
hash4525F4FE895D887AE354CE6221BAD424690503DAFEBC87A43CF54092FAA9CBE8
hashC1806E59BAE8CD3A320FB249223852D25DD62299844CF045D5AF4AE1DF0452AF
filenamesoo.jar
filename1.jar
hash164de09635532bb0a4fbe25ef3058b86dac332a03629fc91095a4c7841b559da
ip93.171.216.118
ip93.188.161.235
hash1218d79fca1aca48e13a5e6e582cdc5c4d24c3367328c56d61d975a757509335
hashac9294849559c94d5e85cb113ce8ca61bca2e576a97a9e81f66321496ddada61
hash5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05fc09751d09a08e
hasha26f3225aa7e7b5263033dee682153fb7a4332429782c5755a9eaebe8a5df095
hashD667833E4915C385321B553785732BBED3009C2A
hash334eeaf5ea3920b612b4e26bbe3e0cccbc431c2e
filenamentsys391.exe
pathC:\Documents and Settings\Administrator\Application Data\ Broker services\WbemMonitor .exe
urlhxxp://93.188.161[.]235/check2/muees27jxt/shot.jpg
urlhxxp://93.188.161[.]235/check2/muees27jxt/tl.jpg
urlhxxp://93.188.161[.]235/check2/muees27jxt/fl.jpg
urlhxxp://93.188.161[.]235/check2/muees27jxt/inf.jpg
domainwww.rouleta.org
domaintsp-team.com
domainwww.air-bilet.ru
domainwww.cook-n-eat.net
domainwww.preotech.ru
filenameianlar.jar
path/load_module.php?user=
snort
SIDs: 23273 - 23277
snort
SIDs: 26569 through 26572, 26603 and 26668
  • CVE-2012-1723 exploits the getClassLoader (classloader confusion) vulnerability — by modifying a class file by hand, you can confuse the Java runtime between a static variable and an instance variable, resulting in code executing outside the Java sandbox.
  • Malicious JAR grants itself full permissions by overloading java.security.AllPermission — look for this pattern in JAR class analysis.
  • The exploit leverages java.security.PrivilegedExceptionAction and downloads an executable to the Java temp directory, saved as ntsys391.exe.
  • LightsOut EK only serves the malicious JPG payload if the User-Agent matches 'Opera/10.35 Presto/2.2.30' — use this as a network detection trigger.
  • Bleeding Life EK landing page URI pattern: /load_module.php?user= with values n1, 1, 2, or 11 (regex: user=(n1|11?|2)) — use for URI-based detection.
  • JavaScript IDS evasion in LightsOut EK encodes strings by embedding digits that must be removed to reveal the plaintext (e.g., 'forName').
  • Fiesta EK delivers CVE-2012-1723 payload as 'ianlar.jar' — filename can be used as a network or endpoint detection indicator.
  • Blackhole EK delivers CVE-2012-1723 as 'soo.jar' — monitor HTTP responses delivering JAR files with this filename.
  • ·The r7 JAR (CVE-2012-1723) in LightsOut EK may be dynamically built per-request by PHP, meaning the hardcoded download URL and file hashes may vary per compromised host.
  • ·Bleeding Life EK shifted from explicit vulnerability-named URIs (e.g., /modules/helpers/Java-2010-0842.jar) to generic names (e.g., /modules/1.jar), reducing URI-based detection reliability.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.