cvedb.io
CVE-2012-4681
CRITICAL · CVSS 9.8 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 100%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2022-03-03 · Last modified 2026-08-04T05:16:26.010

Summary

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

Affected products

Oracle — Java SE

Does this affect you?

Add your gear to cvedb and we'll alert you only when Oracle ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.