CVE-2012-1723 is a remote code execution vulnerability in the HotSpot component of Oracle Java Runtime Environment and Java SE, affecting Java SE 7 Update 4 and earlier, 6 Update 32 and earlier, 5 Update 35 and earlier, and 1.4.2_37 and earlier. Public reporting and exploit-kit telemetry consistently describe it as a Java applet field bytecode verifier cache or classloader confusion issue in which a malicious Java applet can trigger improper bytecode verification and escape intended sandbox restrictions. In practical exploitation, attackers delivered a crafted JAR or applet through web pages and exploit kits, after which the vulnerable JRE executed attacker-controlled code outside the normal Java security model. The vulnerability was widely weaponized in drive-by download campaigns and watering-hole operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: 'java_verifier_field_access.rb', which exploits CVE-2012-1723, a vulnerability in the Java Runtime Environment's bytecode verifier. The exploit leverages a flaw in the handling of certain bytecode instructions, allowing an attacker to escape the Java sandbox and execute arbitrary code on the victim's system. The module sets up a malicious HTTP server that serves a crafted Java applet (CVE-2012-1723.jar) to the victim's browser. When the victim visits the attacker's page, the applet exploits the vulnerability, and the attacker can deliver a payload such as a reverse shell or platform-specific executable. The module supports multiple platforms (Java, Windows, Mac OS X, Linux) and payload types, making it highly weaponized and flexible. The only fingerprintable endpoint is the malicious JAR file served to the victim. The code is structured as a typical Metasploit exploit module, with methods for handling HTTP requests, generating payloads, and serving the malicious applet.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in certain Java versions used in a drive-by exploit to download and execute the RecJS installer.
A Java applet remote code execution vulnerability listed among exploited CVEs.
A vulnerability heavily used by ransomware variants (details not specified in content).
A vulnerability heavily represented in exploit kits, showing broad exploit-pack weaponization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.