CVE-2012-1723 is a critical vulnerability in Oracle Java SE, affecting versions 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier, specifically within the Hotspot component of the Java Runtime Environment. This flaw allows remote attackers to compromise confidentiality, integrity, and availability with no user interaction required, as indicated by its CVSS score of 9.8. It is actively exploited in the wild, including in known ransomware campaigns, and has readily available exploit code through Metasploit. The vulnerability has garnered significant community attention and media coverage, highlighting its widespread impact and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.2_37CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:*:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.5.0:-:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.5.0:update1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.5.0:update10:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.5.0:update11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.