Vulnerability record · CVE-2012-4681 · published 28 August 2012
CVE-2012-4681: Oracle Java SE 7 JRE SecurityManager bypass allows remote code execution
Oracle · Jdk
The Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can use ClassFinder.findClass with a forName exception to reach restricted classes such as sun.awt.SunToolkit, then use reflection with a trusted immediate caller to read and modify private fields. This lets untrusted applet code escape the sandbox and run arbitrary code.
Description
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed in-the-wild exploitation, CISA KEV listing with known ransomware use, and an EPSS near 0.99 make this a top remediation priority wherever Java SE 7 Update 6 or earlier remains.
What it is
The Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can use ClassFinder.findClass with a forName exception to reach restricted classes such as sun.awt.SunToolkit, then use reflection with a trusted immediate caller to read and modify private fields. This lets untrusted applet code escape the sandbox and run arbitrary code.
Impact
An attacker gains arbitrary code execution in the context of the Java process, typically the logged-in user. That permits installation of malware, credential theft, or further lateral movement on the host.
Attack surface
Reached remotely over the network by loading a malicious Java applet in a browser or applet container; no authentication is required, but the victim must load the applet, so user interaction is needed. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N, though the description makes clear the applet must be delivered to and executed by the target.
Exploitation
Exploited in the wild in August 2012 using Gondzz.class and Gondvv.class, and listed in CISA KEV with known ransomware campaign use. EPSS is 0.98536 (99.9th percentile), and references include exploit-tagged analyses.
What to do
- Apply the Oracle Java SE 7 update that fixes CVE-2012-4681, or upgrade to a supported Java release; follow the vendor advisory and Red Hat RHSA-2012-1225 for Linux packages.
- Disable or remove the Java browser plug-in where it is not required, and block applet execution in browsers.
- Set Java security settings to the highest level and maintain a restricted exception list so untrusted applets cannot run.
- Restrict outbound network access from Java processes and segment hosts that must retain Java to limit post-exploitation impact.
- Track CISA KEV remediation due dates and confirm the update is applied on all endpoints and servers running JRE/JDK.
Detection
- Monitor for Java processes spawning unexpected child processes such as cmd.exe, powershell.exe, or /bin/sh.
- Alert on applet class names or JAR loads matching Gondzz.class or Gondvv.class, and on applet downloads from untrusted sites.
- Review browser and Java plug-in logs for applet execution events on hosts that should not be running applets.
- Hunt for file writes or registry changes by javaw.exe/java.exe outside expected application directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2012-4681 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4681 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4681), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.