Vulnerability record · CVE-2012-1533 · published 16 October 2012
CVE-2012-1533: Oracle Java SE JRE Deployment component remote code execution flaw
Oracle · Jdk
CVE-2012-1533 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier. It allows remote attackers to affect confidentiality, integrity and availability, and is distinct from CVE-2012-3159. The record gives no root-cause detail, so the exact mechanism is unknown.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-3159.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely reachable with no authentication and yields complete compromise, and EPSS is very high, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
CVE-2012-1533 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier. It allows remote attackers to affect confidentiality, integrity and availability, and is distinct from CVE-2012-3159. The record gives no root-cause detail, so the exact mechanism is unknown.
Impact
Successful exploitation gives an attacker full compromise of confidentiality, integrity and availability, meaning arbitrary code execution in the JRE context. The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C reflects complete impact with no authentication.
Attack surface
Reachable over the network with no authentication required, per the CVSS vector. The Deployment component is typically invoked through browser-hosted Java applets or Web Start, so user interaction such as visiting a malicious page is likely, though the record does not state this explicitly.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.69037 (99.3rd percentile), indicating high predicted exploitation activity. No public exploit or in-the-wild confirmation is documented in this record.
What to do
- Apply the Oracle October 2012 Critical Patch Update or later, which addresses this issue per the vendor advisory.
- Upgrade to a Java SE release newer than 7 Update 7 or 6 Update 35, or remove Java from endpoints where it is not needed.
- Apply the referenced Red Hat, openSUSE and IBM vendor errata for bundled Java distributions.
- Disable the Java browser plug-in and Web Start where business use does not require them.
- Restrict outbound access to untrusted sites and enforce Java security settings that block unsigned applets.
Detection
- Monitor for Java processes spawning unexpected child processes such as cmd.exe, powershell.exe or /bin/sh.
- Alert on JRE versions below 7u7 or 6u35 present on endpoints via software inventory.
- Review proxy and DNS logs for requests to known exploit-hosting or drive-by domains serving JAR content.
- Watch for anomalous file writes or network connections originating from javaw.exe or java processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1533 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1533), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.