cbcvebase.
CVE-2013-2465
published 2013-06-18

CVE-2013-2465: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45…

PriorityP196critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
98.70%
99.9th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

Affected

22 ranges
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre
oraclejre
oraclejre
sunjdk
sunjdk
sunjre
sunjre
suselinux_enterprise_desktop
suselinux_enterprise_java
suselinux_enterprise_java
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_software_development_kit

Detection & IOCsextracted from sources · hover to see the quote

hashC43DBBADD79F2C50F67BFC265825FBAC3887F6840B1DBB2E2556148F597D80C7
hash7F04E3B43FA259984AEE7CF9FBE83A2C0994FB321D650E5B9FDFDFB11435F05E
hashC9450462F9A58C2C854E93FF8A6782C7AF677653097347F20DD679939EA19B5A
hash164de09635532bb0a4fbe25ef3058b86dac332a03629fc91095a4c7841b559da
hashD667833E4915C385321B553785732BBED3009C2A
hash1218d79fca1aca48e13a5e6e582cdc5c4d24c3367328c56d61d975a757509335
hashac9294849559c94d5e85cb113ce8ca61bca2e576a97a9e81f66321496ddada61
hash5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05fc09751d09a08e
hasha26f3225aa7e7b5263033dee682153fb7a4332429782c5755a9eaebe8a5df095
hash334eeaf5ea3920b612b4e26bbe3e0cccbc431c2e
ip93.171.216.118
ip93.188.161.235
domainwww.rouleta.org
domaintsp-team.com
domainwww.air-bilet.ru
domainwww.cook-n-eat.net
domainwww.preotech.ru
url/load_module.php?user=
url/modules/1.jar
url/check_value.php
url/check2/muees27jxt/shot.jpg
pathC:\Documents and Settings\Administrator\Application Data\ Broker services\WbemMonitor .exe
filenamentsys391.exe
uaOpera/10.35 Presto/2.2.30
urldtsrc.php?a=dwe
snort
SIDs: 26569 through 26572, 26603 and 26668
snort
SIDs: 31229-31232
  • JavaScript obfuscation in the LightsOut EK encodes class names by embedding digits that must be stripped; e.g., the string '836f4974362o65679305r82637150N61617044a77736359m99323481e9388' decodes to 'forName' after removing all digits.
  • Bleeding Life EK landing page URI pattern shifted to /load_module.php?user= with values matching user=(n1|11?|2); monitor web proxy logs for this pattern.
  • ·The Metasploit module for CVE-2013-2465 does not bypass click-to-play protections; exploitation requires Java applets to be permitted to run.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu3.6LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.