Vulnerability record · CVE-2013-2465 · published 18 June 2013
CVE-2013-2465: Oracle Java SE JRE 2D sandbox bypass and code execution
Oracle · Jre
CVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7). Oracle's advisory gives no technical detail, but a third-party vendor claims it allows remote attackers to bypass the Java sandbox via incorrect image channel verification in 2D. Because it is remotely reachable without authentication and can affect confidentiality, integrity and availability, it is a serious client-side risk.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, and a 0.987 EPSS probability make this an actively exploited remote code execution flaw.
What it is
CVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7). Oracle's advisory gives no technical detail, but a third-party vendor claims it allows remote attackers to bypass the Java sandbox via incorrect image channel verification in 2D. Because it is remotely reachable without authentication and can affect confidentiality, integrity and availability, it is a serious client-side risk.
Impact
An attacker can escape the Java sandbox and run code with the privileges of the JVM process, gaining full control of confidentiality, integrity and availability on the host. In practice this means arbitrary code execution on any machine that loads the malicious Java content.
Attack surface
Reached over the network (AV:N) with no privileges and no user interaction required per the CVSS vector, typically by delivering malicious Java content to a JRE. The description does not specify the exact delivery path, so the vector is inferred from the CVSS metrics rather than stated in the record.
Exploitation
CVE-2013-2465 is listed in CISA KEV (added 2022-03-28, due 2022-04-18) with known ransomware campaign use, and EPSS gives a 30-day probability of 0.987 (99.9th percentile). The record contains no exploit code or public PoC reference, but KEV and EPSS indicate active exploitation.
What to do
- Apply the vendor updates referenced in the Oracle June 2013 CPU advisory and the OpenJDK patch; this is the only complete fix.
- Upgrade to a supported Java release; Java 7 Update 21, 6 Update 45 and 5.0 Update 45 and earlier are affected.
- If legacy Java cannot be removed, disable the Java browser plug-in and block execution of untrusted JAR/applet content.
- Apply the Linux distribution errata (Red Hat, SUSE, Gentoo, Mandriva) for hosts running the bundled JRE.
- Restrict outbound and inbound paths that deliver Java content to reduce exposure until patching completes.
Detection
- Hunt for JRE versions at or below 7u21, 6u45 and 5.0u45 on endpoints and servers, including bundled JREs in third-party software.
- Monitor for unexpected child processes spawned by java/javaw, especially browsers or office applications launching Java.
- Alert on Java processes making outbound network connections or writing executables to user-writable directories.
- Review proxy and IDS logs for delivery of JAR or applet content from untrusted or newly seen hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-2465 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Oracle Java SE Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2465 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2465), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.