← Vulnerability feed

Vulnerability record · CVE-2012-4681 · published 28 August 2012

CVE-2012-4681: Oracle Java SE 7 JRE SecurityManager bypass allows remote code execution

Oracle · Jdk

The Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can use ClassFinder.findClass with a forName exception to reach restricted classes such as sun.awt.SunToolkit, then use reflection with a trusted immediate caller to read and modify private fields. This lets untrusted applet code escape the sandbox and run arbitrary code.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2022 Known ransomware use EPSS 99% · top 0.1% CWE-284 · Improper access control
9.8CVSS 3.1 base score, v2 10.0
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
27References, 4 tagged exploit
6 Aug 2026Last modified by NVD

Description

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, confirmed in-the-wild exploitation, CISA KEV listing with known ransomware use, and an EPSS near 0.99 make this a top remediation priority wherever Java SE 7 Update 6 or earlier remains.

What it is

The Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can use ClassFinder.findClass with a forName exception to reach restricted classes such as sun.awt.SunToolkit, then use reflection with a trusted immediate caller to read and modify private fields. This lets untrusted applet code escape the sandbox and run arbitrary code.

Impact

An attacker gains arbitrary code execution in the context of the Java process, typically the logged-in user. That permits installation of malware, credential theft, or further lateral movement on the host.

Attack surface

Reached remotely over the network by loading a malicious Java applet in a browser or applet container; no authentication is required, but the victim must load the applet, so user interaction is needed. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N, though the description makes clear the applet must be delivered to and executed by the target.

Exploitation

Exploited in the wild in August 2012 using Gondzz.class and Gondvv.class, and listed in CISA KEV with known ransomware campaign use. EPSS is 0.98536 (99.9th percentile), and references include exploit-tagged analyses.

What to do

  • Apply the Oracle Java SE 7 update that fixes CVE-2012-4681, or upgrade to a supported Java release; follow the vendor advisory and Red Hat RHSA-2012-1225 for Linux packages.
  • Disable or remove the Java browser plug-in where it is not required, and block applet execution in browsers.
  • Set Java security settings to the highest level and maintain a restricted exception list so untrusted applets cannot run.
  • Restrict outbound network access from Java processes and segment hosts that must retain Java to limit post-exploitation impact.
  • Track CISA KEV remediation due dates and confirm the update is applied on all endpoints and servers running JRE/JDK.

Detection

  • Monitor for Java processes spawning unexpected child processes such as cmd.exe, powershell.exe, or /bin/sh.
  • Alert on applet class names or JAR loads matching Gondzz.class or Gondvv.class, and on applet downloads from untrusted sites.
  • Review browser and Java plug-in logs for applet execution events on hosts that should not be running applets.
  • Hunt for file writes or registry changes by javaw.exe/java.exe outside expected application directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-4681 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html Third Party Advisory
http://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.html ExploitThird Party Advisory
http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/ Broken LinkExploit
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html Mailing List
http://marc.info/?l=bugtraq&m=135109152819176&w=2 Issue TrackingMailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1225.html Third Party Advisory
http://secunia.com/advisories/51044 Not Applicable
http://www.deependresearch.org/2012/08/java-7-vulnerability-analysis.html Broken LinkThird Party Advisory
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html Vendor Advisory
http://www.securityfocus.com/bid/55213 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA12-240A.html Third Party AdvisoryUS Government Resource
https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day Broken LinkThird Party Advisory
http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html Third Party Advisory
http://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.html ExploitThird Party Advisory
http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/ Broken LinkExploit
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html Mailing List
http://marc.info/?l=bugtraq&m=135109152819176&w=2 Issue TrackingMailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1225.html Third Party Advisory
http://secunia.com/advisories/51044 Not Applicable
http://www.deependresearch.org/2012/08/java-7-vulnerability-analysis.html Broken LinkThird Party Advisory
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html Vendor Advisory
http://www.securityfocus.com/bid/55213 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA12-240A.html Third Party AdvisoryUS Government Resource
https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day Broken LinkThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-4681 US Government Resource

Track CVE-2012-4681 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2012-4681), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.