CVE-2012-1533 is a critical vulnerability affecting the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and 6 Update 35 and earlier versions, specifically involving the Deployment subsystem. With a maximum CVSS score of 10.0, this flaw allows unauthenticated remote attackers to execute arbitrary code via network vectors, potentially resulting in a complete compromise of system confidentiality, integrity, and availability. Although there is no recent community discussion or CISA KEV listing, the vulnerability presents a confirmed risk due to the availability of functional remote code execution exploits in Metasploit and ExploitDB targeting a double quote injection in Java Web Start.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:*:update7:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.