Vulnerability record · CVE-2012-0500 · published 15 February 2012
CVE-2012-0500: Oracle Java SE Deployment flaw allows untrusted applets to compromise systems
Oracle · Jre
CVE-2012-0500 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier. Because the flaw is unspecified, the exact mechanism is unknown, but it lets remote untrusted Java Web Start applications and untrusted applets affect confidentiality, integrity, and availability. It matters because Java was widely deployed and applet/Web Start execution was a common browser-reachable path.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10.0 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus a 99th-percentile EPSS score, make this a top remediation priority despite the lack of confirmed exploitation.
What it is
CVE-2012-0500 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier. Because the flaw is unspecified, the exact mechanism is unknown, but it lets remote untrusted Java Web Start applications and untrusted applets affect confidentiality, integrity, and availability. It matters because Java was widely deployed and applet/Web Start execution was a common browser-reachable path.
Impact
An attacker can fully compromise confidentiality, integrity, and availability of the affected system, consistent with the CVSS 2.0 score of 10.0. In practice this means code execution or equivalent total loss of protection on the host running the vulnerable JRE.
Attack surface
Reached remotely over the network with no authentication, per the AV:N/AC:L/Au:N vector. The description states the attack comes through untrusted Java Web Start applications and untrusted Java applets, so some form of user action to load that content is implied even though the vector does not list user interaction.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high (0.59243, 99th percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Apply the Oracle February 2012 Critical Patch Update or later Java SE/JRE release that fixes CVE-2012-0500, and apply the referenced Red Hat and openSUSE errata on Linux distributions.
- Upgrade to a supported Java version; Java SE 6 Update 30, 7 Update 2, and JavaFX 2.0.2 and earlier are affected and long out of support.
- Disable or remove the Java browser plug-in and Java Web Start where not required, and block untrusted applet/Web Start execution.
- Restrict outbound and inbound Java deployment traffic and enforce allowlisting so untrusted JNLP/applet content cannot be loaded.
- Where Java is still needed, isolate it in a hardened, non-privileged environment with least-privilege execution.
Detection
- Monitor for Java Web Start (javaws) and browser plug-in processes spawning unexpected child processes or writing to system directories.
- Alert on JNLP file downloads and applet loads from untrusted or newly seen hosts, especially outside approved application sources.
- Inventory endpoints for Java SE 6 Update 30 or earlier, Java SE 7 Update 2 or earlier, and JavaFX 2.0.2 or earlier and flag them for remediation.
- Review proxy and endpoint logs for Java deployment traffic to low-reputation domains that could deliver malicious applets or JNLP content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0500 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0500), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.