← Vulnerability feed

Vulnerability record · CVE-2012-1723 · published 16 June 2012

CVE-2012-1723: Oracle Java SE Hotspot Improper Access Control Enables Remote Code Execution

Oracle · Jdk

CVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier. It allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, and is classified as CWE-284 improper access control. The flaw is severe because it can be triggered without authentication or user interaction and has been exploited in the wild.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2022 Known ransomware use EPSS 94% · top 0.2% CWE-284 · Improper access control
9.8CVSS 3.1 base score, v2 10.0
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
8Affected product versions listed by NVD
21References
6 Aug 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS score is 9.8, the vulnerability is in CISA KEV with known ransomware use, and EPSS probability is extremely high, indicating active and severe risk.

What it is

CVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier. It allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, and is classified as CWE-284 improper access control. The flaw is severe because it can be triggered without authentication or user interaction and has been exploited in the wild.

Impact

A remote attacker can fully compromise confidentiality, integrity, and availability, potentially leading to arbitrary code execution in the context of the Java process. This can result in system takeover, data theft, or service disruption.

Attack surface

The vulnerability is reachable over the network (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), likely via a crafted Java application or applet processed by the JRE. No authentication is needed to trigger the flaw.

Exploitation

CVE-2012-1723 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware campaign use, and EPSS indicates a 93.7% probability of exploitation in the next 30 days, confirming active exploitation.

What to do

  • Apply the latest Oracle Java SE updates or the vendor patches referenced in the Oracle June 2012 CPU advisory immediately.
  • Upgrade to a supported Java version and remove or disable outdated JRE versions (7u4, 6u32, 5u35, 1.4.2_37 and earlier).
  • Disable Java browser plugins and restrict Java execution to trusted applications where possible.
  • Apply Red Hat, Gentoo, and other vendor errata for affected Linux distributions.
  • Monitor for and block exploitation attempts using network and endpoint controls.

Detection

  • Monitor for unusual Java process behavior, such as spawning child processes or making unexpected network connections.
  • Inspect Java applet and Web Start application execution logs for suspicious activity.
  • Use endpoint detection to flag exploitation attempts targeting Hotspot or JRE components.
  • Review network traffic for known exploit patterns or payloads associated with CVE-2012-1723.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-1723 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html Mailing List
http://marc.info/?l=bugtraq&m=134496371727681&w=2 Mailing List
http://rhn.redhat.com/errata/RHSA-2012-0734.html Third Party Advisory
http://secunia.com/advisories/51080 Broken Link
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://www.ibm.com/support/docview.wss?uid=swg21615246 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2012:095 Broken Link
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html Vendor Advisory
http://www.securityfocus.com/bid/53960 Broken LinkThird Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16259 Broken Link
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html Mailing List
http://marc.info/?l=bugtraq&m=134496371727681&w=2 Mailing List
http://rhn.redhat.com/errata/RHSA-2012-0734.html Third Party Advisory
http://secunia.com/advisories/51080 Broken Link
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://www.ibm.com/support/docview.wss?uid=swg21615246 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2012:095 Broken Link
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html Vendor Advisory
http://www.securityfocus.com/bid/53960 Broken LinkThird Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16259 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1723 US Government Resource

Track CVE-2012-1723 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1723), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.