CVE detail
CVE-2013-0422
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114. CVE-2013-0422 covers both the JMX/MBean and Reflection API issues. NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks. NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11. If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
19 source links · newest first
Another day, another news about a clamorous data breach, this time the Reuters agency revealed that Microsoft suffered a major security breach back in 2013. According to five former employees, hackers broke into the company vulnerabilities and bug reports database, but the news was never disclosed. The former employees explained that Microsoft addressed all the […]
newssecurityaffairs.comOct 17, 2017, 11:15 AMWhat is old may not always be new, but when it comes to hacking, it’s still effective.
newswww.securityweek.comFeb 23, 2015, 11:26 PM- Why do we need for Incident Response plan?Security Affairs
Due to the constant growth in the number of cyber attacks it is necessary to properly define the actions composing an incident response plan. FireEye firm published an interesting post on the need of incident response (IR) capabilities to reply numerous cyber attacks that daily hit almost any web service. Starting from the data proposed […]
newssecurityaffairs.comNov 26, 2013, 7:58 PM Several media sites, including two Washington, DC-based radio stations, have been compromised to infect unsuspecting visitors’ systems with fake antivirus software.
newswww.securityweek.comMay 7, 2013, 5:24 PM- Redkit Exploit Kit does the splitsMalwarebytes Labs
Exploit Kit authors must really love Java . Not only is it ripe with vulnerabilities but its own language provides a…
newswww.malwarebytes.comApr 4, 2013, 5:00 PM - Malware in a JarMalwarebytes Labs
As researchers find more security flaws in Oracle Java, the software continues to be used for exploitation and malware delivery. This…
newswww.malwarebytes.comApr 2, 2013, 5:00 PM - MiniDuke Attack Leveraged IE, Java ExploitsSecurityWeek
Researchers at Kaspersky Lab and Crysys Lab have discovered two previously-unknown infections mechanisms for MiniDuke, the cyber-espionage malware linked to attacks across the globe.
newswww.securityweek.comMar 11, 2013, 3:12 PM - MiniDuke does not come only via emailHelp Net Security
Researchers from Kaspersky and CrySyS Lab continue to analyze the MiniDuke backdoor and have discovered two previously unknown infection mechanisms. Recently discovered to have been used to attack multiple government entities and institutions worldwide, MiniDuke is highly customized and very small in size, and was spotted being delivered to victims via malicious PDF documents rigged with exploits attacking Adobe Reader versions 9, 10, and 11, bypassing its sandbox. But, as it turns out, this might … More →
newswww.helpnetsecurity.comMar 11, 2013, 3:10 PM - Whitehole Exploit Kit in the wildSecurity Affairs
Exploit kit, a name which has become depressingly familiar, crimaware kit that contains malicious code to exploit principal vulnerabilities in large consume product such as browsers, last news is that a new kit named Whitehole has emerged on the underground market. Generally the exploit kits are malicious Web-based applications designed to install malware on computers […]
newssecurityaffairs.comFeb 9, 2013, 7:13 AM The name BlackHole looms large over the marketplace for crimeware kits, but a new player is said to have emerged with similar code and a similar name.
newswww.securityweek.comFeb 7, 2013, 4:02 PMA new exploit kit called Whitehole has emerged on the underground market, providing cybercriminals with one more tool to infect computers with malware over the Web, security researchers from antivirus vendor Trend Micro reported Wednesday. Exploit kits are malicious Web-based applications designed to install malware on computers by exploiting vulnerabilities in outdated browser plug-ins like […]
newswww.csoonline.comFeb 7, 2013, 3:00 PM- Whitehole exploit kit in the spotlightHelp Net Security
The effectiveness of exploit kits has made them malware peddlers’ preferred way of distributing their malicious wares. The Blackhole exploit kit is, by far, the most most used one, and has pretty much cornered the market at the moment, but there are other kits out there looking to challenge its supremacy. Among them is a new exploit kit that has been dubbed “Whitehole” by researchers for the simple reason of differentiating it from Blackhole. Whitehole … More →
newswww.helpnetsecurity.comFeb 7, 2013, 8:08 AM - Malwarebiter – Biting down on youMalwarebytes Labs
UPDATE: As of 1/28, the Facebook page for Malwarebiter appears to have been deleted.Overview A few days ago Malwarebytes Intelligence Analyst Adam…
newswww.malwarebytes.comJan 29, 2013, 5:00 PM Watering hole attacks continue unabated and, according to Avast’s Director of Threat Intelligence Jindrich Kubec, the finger could be safely pointed to China once again. The latest website compromised to redirect visitors to sites serving exploits for the recently patched IE zero-day vulnerability and two Java flaws (CVE-2013-0422 and CVE-2011-3544) is the official site of Reporters Without Borders (Reporters sans Frontières), an international non-governmental organization advocating freedom of the press and freedom of information. “Such … More →
newswww.helpnetsecurity.comJan 24, 2013, 10:48 AMThe website for Reporters Without Borders was booby-trapped to deliver malicious software using the latest Java and Internet Explorer vulnerabilities, security vendor Avast said on Tuesday. Reporters Without Borders, based in Paris, is an international advocate for press freedom. Avast, which discovered the site had been tampered with, said the group’s profile makes it “an […]
newswww.csoonline.comJan 22, 2013, 3:00 PM- What the latest Java flaw really meansCSO Online
The latest Java zero-day flaw has the tech world in an uproar. This newest hole, actively exploited in the wild, was patched by Oracle yesterday — only to have multiple ultratrusted security gurus saying Oracle didn’t address every bug and some even maintaining it could take Oracle two years to fix all the vulnerabilities. You know […]
newswww.csoonline.comJan 15, 2013, 2:00 PM After the Department of Homeland Security’s US-CERT warned users to disable Java to stop hackers from taking control of users’ machines, Oracle issued an emergency patch on Sunday. Last week, Carnegie Mellon University (CMU) Software Engineering Institute (SEI) CERT Program warned that the newest Java “vulnerability is being attacked in the wild, and is reported […]
newswww.csoonline.comJan 14, 2013, 6:59 PMOracle released two out-of-band patches on Sunday for vulnerabilities in its Java programming language, both of which pose a high risk to users browsing the web. The company’s speed in issuing patches may be due to part that exploit code for at least one of the vulnerabilities, CVE-2013-0422, has already been wrapped into two “exploit […]
newswww.csoonline.comJan 13, 2013, 3:00 PM- New security problem for Oracle Java softwareSecurity Affairs
The year is start way for Oracle Java platform, a new Java 0-day vulnerability has been discovered and worldwide security community is very concerned on the potential effect of the bug. We have discovered how much dangerous could be the exploit of a zero-day vulnerability especially against institutional targets and governments (e.g. Elderwood project), state-sponsored hackers […]
newssecurityaffairs.comJan 12, 2013, 2:27 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-3427CVSS 9.8 · Critical
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and ava…
- CVE-2015-4902CVSS 5.3 · Medium
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
- CVE-2013-2423CVSS 3.7 · Low
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via…
- CVE-2011-3544CVSS 9.8 · Critical
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications…
- CVE-2016-9843CVSS 9.8 · Critical
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
- CVE-2016-9842CVSS 8.8 · High
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.