CVE-2012-1723
published 2012-06-16CVE-2012-1723: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
93.69%
99.8th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.4.2_37 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.4.2_37 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | icedtea6 | < 1.10.8 | 1.10.8 |
| redhat | icedtea6 | >= 1.11.0 < 1.11.3 | 1.11.3 |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs: 23273 - 23277
snort↗
SIDs: 26569 through 26572, 26603 and 26668
- →CVE-2012-1723 exploits the getClassLoader (classloader confusion) vulnerability — by modifying a class file by hand, you can confuse the Java runtime between a static variable and an instance variable, resulting in code executing outside the Java sandbox. ↗
- →Malicious JAR grants itself full permissions by overloading java.security.AllPermission — look for this pattern in JAR class analysis. ↗
- →The exploit leverages java.security.PrivilegedExceptionAction and downloads an executable to the Java temp directory, saved as ntsys391.exe. ↗
- →LightsOut EK only serves the malicious JPG payload if the User-Agent matches 'Opera/10.35 Presto/2.2.30' — use this as a network detection trigger. ↗
- →Bleeding Life EK landing page URI pattern: /load_module.php?user= with values n1, 1, 2, or 11 (regex: user=(n1|11?|2)) — use for URI-based detection. ↗
- →JavaScript IDS evasion in LightsOut EK encodes strings by embedding digits that must be removed to reveal the plaintext (e.g., 'forName'). ↗
- →Fiesta EK delivers CVE-2012-1723 payload as 'ianlar.jar' — filename can be used as a network or endpoint detection indicator. ↗
- →Blackhole EK delivers CVE-2012-1723 as 'soo.jar' — monitor HTTP responses delivering JAR files with this filename. ↗
- ·The r7 JAR (CVE-2012-1723) in LightsOut EK may be dynamically built per-request by PHP, meaning the hardcoded download URL and file hashes may vary per compromised host. ↗
- ·Bleeding Life EK shifted from explicit vulnerability-named URIs (e.g., /modules/helpers/Java-2010-0842.jar) to generic names (e.g., /modules/1.jar), reducing URI-based detection reliability. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
cisa·2022-03-03·CVSS 9.8
CVE-2012-1723 [CRITICAL] Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Vulnerability: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Affected: Oracle Java SE
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1723
Remediation Due Date: 2022-03-24
Ubuntu
IcedTea-Web regression
vendor_ubuntu·2012-08-30·CVSS 7.5
[HIGH] IcedTea-Web regression
Title: IcedTea-Web regression
Summary: USN 1505-1 introduced a regression in the IcedTea-Web Java web browser
plugin that prevented it from working with the Chromium web browser.
USN-1505-1 fixed vulnerabilities in OpenJDK 6. As part of the update,
IcedTea-Web packages were upgraded to a new version. That upgrade
introduced a regression which prevented the IcedTea-Web plugin from
working with the Chromium web browser in Ubuntu 11.04 and Ubuntu 11.10.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that multiple flaws existed in the CORBA (Common
Object Request Broker Architecture) implementation in OpenJDK. An
attacker could create a Java application or applet that used these
flaws to bypass Java sandbox restrictions or m
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2012-07-13·CVSS 7.5
CVE-2012-1711 [HIGH] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that multiple flaws existed in the CORBA (Common
Object Request Broker Architecture) implementation in OpenJDK. An
attacker could create a Java application or applet that used these
flaws to bypass Java sandbox restrictions or modify immutable object
data. (CVE-2012-1711, CVE-2012-1719)
It was discovered that multiple flaws existed in the OpenJDK font
manager's layout lookup implementation. A attacker could specially
craft a font file that could cause a denial of service through
crashing the JVM (Java Virtual Machine) or possibly execute arbitrary
code. (CVE-2012-1713)
It was discovered that the SynthLookAndFeel class from Swing in
OpenJDK did not properly prevent access to cert
Red Hat
OpenJDK: insufficient field accessibility checks (HotSpot, 7152811)
vendor_redhat·2012-06-12·CVSS 9.8
CVE-2012-1723 [CRITICAL] OpenJDK: insufficient field accessibility checks (HotSpot, 7152811)
OpenJDK: insufficient field accessibility checks (HotSpot, 7152811)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
GHSA
GHSA-ch9c-pq9h-jrr9: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update
ghsa_unreviewed·2022-05-14
CVE-2012-1723 [HIGH] CWE-284 GHSA-ch9c-pq9h-jrr9: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
VulnCheck
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
vulncheck·2012·CVSS 9.8
CVE-2012-1723 [CRITICAL] Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.
Affected: Oracle Java SE
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://blog.malwarebytes.com/threat-analysis/2013/03/new-exploit-kit-ransomware-and-av-evasion/; https://cybersecurity.att.com/blogs/labs-research/new-sykipot-developments; https://blogs.cisco.com/security/watering-hole-attacks-target-energy-sector; https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2013/hidden_lynx.pdf; https://securelist.com/th
No detection rules found.
Exploit-DB
Java Applet - Field Bytecode Verifier Cache Remote Code Execution (Metasploit)
exploitdb·2012-07-11·CVSS 9.8
CVE-2012-1723 [CRITICAL] Java Applet - Field Bytecode Verifier Cache Remote Code Execution (Metasploit)
Java Applet - Field Bytecode Verifier Cache Remote Code Execution (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 false })
def initialize( info = {} )
super( update_info( info,
'Name' => 'Java Applet Field Bytecode Verifier Cache Remote Code Execution',
'Description' => %q{
This module exploits a vulnerability in HotSpot bytecode verifier where an invalid
optimisation of GETFIELD/PUTFIELD/GETSTATIC/PUTSTATIC instructions leads to insufficent
type checks. This allows a way to escape the JRE sandbox, and load additional classes
i
Metasploit
Java Applet Field Bytecode Verifier Cache Remote Code Execution
metasploit
Java Applet Field Bytecode Verifier Cache Remote Code Execution
Java Applet Field Bytecode Verifier Cache Remote Code Execution
This module exploits a vulnerability in HotSpot bytecode verifier where an invalid optimization of GETFIELD/PUTFIELD/GETSTATIC/PUTSTATIC instructions leads to insufficient type checks. This allows a way to escape the JRE sandbox, and load additional classes in order to perform malicious operations.
Trendmicro
Examining the Activities of the Turla APT Group
blogs_trendmicro·2023-09-22·CVSS 9.8
[CRITICAL] Examining the Activities of the Turla APT Group
APT & Targeted Attacks
# Examining the Activities of the Turla APT Group
We examine the campaigns of the cyberespionage group known as Turla over the years, with a special focus on the key MITRE techniques and the corresponding IDs associated with the threat actor group.
By: Srivathsa Sharma
2023/09/22
Read time: ( words)
Save to Folio
In this blog entry, we examine the campaigns of the cyberespionage group known as Turla over the years, with a special focus on the key MITRE techniques and the corresponding IDs associated with the threat actor group.
An introduction to Turla
Regarded as a highly sophisticated advanced persistent threat (APT) group, the Russian-based Turla has been suspected to be operational since at least 2004.
Turla’s group names are infamously titled after its
Qualys
Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
#### Table of Contents
- Stats on the Top 20 Vulnerable Vendors & By-Products
- Top Twenty Most Targeted by Attackers
- TruRisk Dashboard
- Key Insights & Takeaways
- References
- Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the curre
Qualys
Qualys Top 20 Most Exploited Vulnerabilities
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Qualys Top 20 Most Exploited Vulnerabilities
## Table of Contents
Stats on the Top 20 Vulnerable Vendors & By-Products
Top Twenty Most Targeted by Attackers
TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the current year.
Qualys
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
blogs_qualys·2023-07-18
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
## Table of Contents
Top Ten Vulnerabilities Exploited by Threat Actors
Top Ten Highly Active Threat Actors
Top Ten Most Exploited Vulnerabilities by Malware
Top Ten Most Active Malware
Top Ten Vulnerabilities Exploited by Ransomware
Prioritizing Exploited Vulnerabilities with TheQualys VMDR and TruRisk
Assess Your Organizations Exposure to Risk / TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributor
The previous blog from this three-part series showcased an overview of the vulnerability threat landscape. To summarize quickly, it illustrated the popular methods of exploiting vulnerabilities and the tactical techniques employed by threat actors, malware, and ransomware groups. Perhaps more crucially, we stated that commonly used solutions (CISA KEV/EPSS) of
Qualys
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research
blogs_qualys·2021-10-05
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research
## Table of Contents
Clear guidelines from authorities for ransomware prevention
Qualys undertakes research on ransomware to deliver actionable insights
Challenges in following guidelines for preventing ransomware attacks
Assess & continuously monitor your ransomware risk, powered by Qualys Research
Learn more and see for yourself
Resources
References
Ransomware attacks are among the most significant cyber threats facing businesses today. Recent warnings about Conti ransomware, issued by a joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), FBI and National Security Agency, are a strong signal that ransomware attacks are becoming even more sophisticated and massive via the ransomware-as-a-service operating model. This new model allows
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
- Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
1. Was our software used outside of its intended functionality to pull classified information from a person’s c
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
Was our software used outside of its intended functionality to pull classified information from a person’s comput
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
- Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
- Internet Explorer: MS14-021 for CVE-2014-1776, Qualys ID: 100191
- MS14-012 for CVE-201
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
MS14-012 for CVE-2014-0322
MS13-038 for CVE-2013-1347
MS13-008 for CVE-2012-4792
MS10-01
Zscaler
Fiesta Exploit Kit: Live Infection | Zscaler
blogs_zscaler·2014-09-29
Fiesta Exploit Kit: Live Infection | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Talos
The never ending Exploit Kit shift - Bleeding Life
blogs_talos·2014-06-12·CVSS 9.8
[CRITICAL] The never ending Exploit Kit shift - Bleeding Life
## The never ending Exploit Kit shift - Bleeding Life
Recently we've been able to observe several shifts in exploit kit techniques, so I thought it would be good to share the IOC information for the exploit kits so that administrators and network defenders can take a look at their devices and logs to remediate on their networks.
## Bleeding Life
Bleeding life, traditionally, was not one of the more subtle exploit kits.
In the past, the exploit kit would attempt to get the exploits through fairly obvious URI methods. For example:
"/load_module.php?e=Adobe-2010-2884"
"/load_module.php?e=Java-2010-3552"
"/modules/helpers/Java-2010-0842.jar"
The URI would be explicit about which vulnerability the kit was going to download and run on the client. However, as of the beginning of of May, s
Talos
The never ending Exploit Kit shift - Bleeding Life
blogs_talos·2014-06-12·CVSS 9.8
[CRITICAL] The never ending Exploit Kit shift - Bleeding Life
Recently we've been able to observe several shifts in exploit kit techniques, so I thought it would be good to share the IOC information for the exploit kits so that administrators and network defenders can take a look at their devices and logs to remediate on their networks.
## Bleeding Life
Bleeding life, traditionally, was not one of the more subtle exploit kits.
In the past, the exploit kit would attempt to get the exploits through fairly obvious URI methods. For example:
"/load_module.php?e=Adobe-2010-2884"
"/load_module.php?e=Java-2010-3552"
"/modules/helpers/Java-2010-0842.jar"
The URI would be explicit about which vulnerability the kit was going to download and run on the client. However, as of the beginning of of May, subtlety increased slightly, as we've seen a shift in th
Talos
Continued analysis of the LightsOut Exploit Kit
blogs_talos·2014-05-02·CVSS 9.8
[CRITICAL] Continued analysis of the LightsOut Exploit Kit
## Continued analysis of the LightsOut Exploit Kit
At the end of March, we disclosed the coverage of an Exploit Kit we called “Hello”: http://blog.talosintel.com/2014/03/hello-new-exploit-kit.html , or “LightsOut”, we thought we’d do a follow up post to tear this exploit kit apart a bit more. This variant of the LightsOut exploit kit uses a number of Java vulnerabilities, and targets multiple browsers. The primary goal is to drop & execute a downloader executable, which in turn downloads and executes more malware samples. These secondary malware samples are run in a sequence, and do some information harvesting, and potentially exfiltrate the information harvested. Overall, not fun for visitors to sites compromised with the LightsOut exploit kit. Because of the number of Java vulnerabiliti
Talos
Continued analysis of the LightsOut Exploit Kit
blogs_talos·2014-05-02·CVSS 9.8
[CRITICAL] Continued analysis of the LightsOut Exploit Kit
At the end of March, we disclosed the coverage of an Exploit Kit we called “Hello”: http://blog.talosintel.com/2014/03/hello-new-exploit-kit.html, or “LightsOut”, we thought we’d do a follow up post to tear this exploit kit apart a bit more. This variant of the LightsOut exploit kit uses a number of Java vulnerabilities, and targets multiple browsers. The primary goal is to drop & execute a downloader executable, which in turn downloads and executes more malware samples. These secondary malware samples are run in a sequence, and do some information harvesting, and potentially exfiltrate the information harvested. Overall, not fun for visitors to sites compromised with the LightsOut exploit kit.
Because of the number of Java vulnerabilities leveraged by this kit; it's important to keep Jav
Krebs
Espionage Hackers Target ‘Watering Hole’ Sites
blogs_krebs·2012-09-25
Espionage Hackers Target ‘Watering Hole’ Sites
Security experts are accustomed to direct attacks, but some of today’s more insidious incursions succeed in a roundabout way — by planting malware at sites deemed most likely to be visited by the targets of interest. New research suggests these so-called “watering hole” tactics recently have been used as stepping stones to conduct espionage attacks against a host of targets across a variety of industries, including the defense, government, academia, financial services, healthcare and utilities sectors.
Espionage attackers increasingly are setting traps at “watering hole” sites, those frequented by individuals and organizations being targeted.
Some of the earliest details of this trend came in late July 2012 from RSA FirstWatch, which warned of an increasingly common attack technique invo
Krebs
Espionage Hackers Target ‘Watering Hole’ Sites – Krebs on Security
blogs_krebs·2012-09-01
Espionage Hackers Target ‘Watering Hole’ Sites – Krebs on Security
Security experts are accustomed to direct attacks, but some of today’s more insidious incursions succeed in a roundabout way — by planting malware at sites deemed most likely to be visited by the targets of interest. New research suggests these so-called “watering hole” tactics recently have been used as stepping stones to conduct espionage attacks against a host of targets across a variety of industries, including the defense, government, academia, financial services, healthcare and utilities sectors.
Espionage attackers increasingly are setting traps at “watering hole” sites, those frequented by individuals and organizations being targeted.
Some of the earliest details of this trend came in late July 2012 from RSA FirstWatch, which warned of an increasingly common attack technique invo
Talos
CVE-2012-1723: New Java Attack Added to Blackhole
blogs_talos·2012-07-09·CVSS 9.8
CVE-2012-1723 [CRITICAL] CVE-2012-1723: New Java Attack Added to Blackhole
## CVE-2012-1723: New Java Attack Added to Blackhole
Word began to emerge last week of the addition of a new vulnerability to the Blackhole Exploit Kit. The bug in question - CVE-2012-1723 - is a complex Java issue, which thankfully has patches available from Oracle already. Of course, just because a patch is available doesn't mean it's been applied - most exploit kits thrive off of reliable exploits of bugs that are often two or more years old - so adding a new, current attack to the Blackhole arsenal will only make it that much more dangerous. Since there are now public writeups , including proof-of-concept exploits, this bug is likely to be a pain in defenders' sides even outside the context of Blackhole.
Like so many other attacks we see these days, we've seen a sample that came in v
Talos
CVE-2012-1723: New Java Attack Added to Blackhole
blogs_talos·2012-07-09·CVSS 9.8
CVE-2012-1723 [CRITICAL] CVE-2012-1723: New Java Attack Added to Blackhole
Word began to emerge last week of the addition of a new vulnerability to the Blackhole Exploit Kit. The bug in question - CVE-2012-1723 - is a complex Java issue, which thankfully has patches available from Oracle already. Of course, just because a patch is available doesn't mean it's been applied - most exploit kits thrive off of reliable exploits of bugs that are often two or more years old - so adding a new, current attack to the Blackhole arsenal will only make it that much more dangerous. Since there are now public writeups, including proof-of-concept exploits, this bug is likely to be a pain in defenders' sides even outside the context of Blackhole.
Like so many other attacks we see these days, we've seen a sample that came in via a reasonably well-done LinkedIn phish:
The new expl
Krebs
New Java Exploit to Debut in BlackHole Exploit Kits
blogs_krebs·2012-07-05·CVSS 9.8
[CRITICAL] New Java Exploit to Debut in BlackHole Exploit Kits
Malicious computer code that leverages a newly-patched security flaw in Oracle’s Java software is set to be deployed later this week to cybercriminal operations powered by the BlackHole exploit pack. The addition of a new weapon to this malware arsenal will almost certainly lead to a spike in compromised PCs, as more than 3 billion devices run Java and many of these installations are months out of date.
I first learned about the new exploit from a KrebsOnSecurity reader named Dean who works in incident response for a financial firm. Dean was trying to trace the source of an infected computer in his network; he discovered the culprit appeared to be a malicious “.jar” file. A scan of the jar file at Virustotal.com showed that it was detected by just one antivirus product (Avira), which flag
Krebs
New Java Exploit to Debut in BlackHole Exploit Kits – Krebs on Security
blogs_krebs·2012-07-01·CVSS 9.8
[CRITICAL] New Java Exploit to Debut in BlackHole Exploit Kits – Krebs on Security
Malicious computer code that leverages a newly-patched security flaw in Oracle’s Java software is set to be deployed later this week to cybercriminal operations powered by the BlackHole exploit pack. The addition of a new weapon to this malware arsenal will almost certainly lead to a spike in compromised PCs, as more than 3 billion devices run Java and many of these installations are months out of date.
I first learned about the new exploit from a KrebsOnSecurity reader named Dean who works in incident response for a financial firm. Dean was trying to trace the source of an infected computer in his network; he discovered the culprit appeared to be a malicious “.jar” file. A scan of the jar file at Virustotal.com showed that it was detected by just one antivirus product (Avira), which flag
Crowdstrike
Blurring of Commodity and Targeted Attack Malware
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Blurring of Commodity and Targeted Attack Malware
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Recorded Future
Tracking Moving Targets: Exploit Kits and CVEs
blogs_recorded_future
Tracking Moving Targets: Exploit Kits and CVEs
# Tracking Moving Targets: Exploit Kits and CVEs
One year ago a notorious programmer Paunch, who coded the Blackhole exploit kit, was arrested and charged for the distribution and sale of his wares. Blackhole was an epic Russian exploit kit, rented and used by thousands for their successful campaigns against a range of targets.
Since Paunch’s arrest, the exploit kit threat landscape has changed significantly as malicious actors have sought out new tool kits. Recorded Future undertook the task of analyzing over 600,000 unique web sources to identify the most prevalent exploit kits, what CVEs they commonly leverage, and what the most vulnerable products are.
To get started, let’s craft a simple query looking for mentions of any exploit kit over the last six months.
###### Click image for
arXiv
MalCVE: Malware Detection and CVE Association Using Large Language Models
arxiv_fulltext·2026-02-02
MalCVE: Malware Detection and CVE Association Using Large Language Models
MalCVE: Malware Detection and CVE Association
Using Large Language Models
Eduard Andrei Cristea
Norwegian University of Science and Technology
Trondheim
Norway
[email protected]
Petter Molnes
Norwegian University of Science and Technology
Trondheim
Norway
[email protected]
Jingyue Li
Norwegian University of Science and Technology
Trondheim
Norway
[email protected]
Cristea, Molnes, and Li
## Abstract
Malicious software attacks are having an increasingly significant economic impact. Commercial malware detection software can be costly, and tools that attribute malware to the specific software vulnerabilities it exploits are largely lacking. Understanding the connection between malware and the vulnerabilities it targets is crucial for analyzing past threats and proactively defending
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
Bugzilla
Blocklist Java versions affected by CVE-2012-1723
bugzilla·2012-08-06·CVSS 9.8
CVE-2012-1723 [CRITICAL] Blocklist Java versions affected by CVE-2012-1723
Blocklist Java versions affected by CVE-2012-1723
In June Oracle released Java updates (Java 7 update 5, Java 6 update 33, etc) and announced flaw CVE-2012-1723. An exploit for this bug was added to the BlackHole exploit kit in July and has also been added to Metasploit for others to use.
Encounters with this new exploit have already surpassed those written against the previous version we blocklisted.
http://blogs.technet.com/b/mmpc/archive/2012/08/01/the-rise-of-a-new-java-vulnerability-cve-2012-1723.aspx
Blocklisting this version is a no-brainer in terms of user safety, though I do recognize that deciding the trade-off in user angst is not quite as simple as I'd like. The graph in the Microsoft article linked above is alarming though.
Discussion:
The block is now staged for Windows
Bugzilla
CVE-2012-1723 OpenJDK: insufficient field accessibility checks (HotSpot, 7152811)
bugzilla·2012-06-06·CVSS 9.8
CVE-2012-1723 [CRITICAL] CVE-2012-1723 OpenJDK: insufficient field accessibility checks (HotSpot, 7152811)
CVE-2012-1723 OpenJDK: insufficient field accessibility checks (HotSpot, 7152811)
The HotSpot Java Virtual Machine (JVM) field lookup code did not properly check accessibility rules and for static / non-static mismatch. A specially-crafted class file could possibly use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via:
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
Fixed in Oracle Java 7 Update 5 and 6 Update 33.
---
The fix for this issue is or will be included in the following IcedTea versions:
* IcedTea6 1.10.8
* IcedTea6 1.11.3
* IcedTea7 2.1.1
* IcedTea7 2.2.1
IcedTea6 releases announcement:
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html
http://blog.fuseyism.com/index.php/2012/06/12/security-i
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlhttp://marc.info/?l=bugtraq&m=134496371727681&w=2http://rhn.redhat.com/errata/RHSA-2012-0734.htmlhttp://secunia.com/advisories/51080http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/support/docview.wss?uid=swg21615246http://www.mandriva.com/security/advisories?name=MDVSA-2012:095http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlhttp://www.securityfocus.com/bid/53960https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16259http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlhttp://marc.info/?l=bugtraq&m=134496371727681&w=2http://rhn.redhat.com/errata/RHSA-2012-0734.htmlhttp://secunia.com/advisories/51080http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/support/docview.wss?uid=swg21615246http://www.mandriva.com/security/advisories?name=MDVSA-2012:095http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlhttp://www.securityfocus.com/bid/53960https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16259https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1723
2012-06-16
Published
2022-03-03
Added to CISA KEV
Exploited in the wild