CVE-2013-0431

MEDIUM(5.3)KEVRansomwareLikely Exploited

Oracle JRE Sandbox Bypass Vulnerability

Description

CVE-2013-0431 is a security sandbox bypass vulnerability in the Oracle Java Runtime Environment (JRE) that allows remote attackers to completely circumvent Java's security sandbox and execute arbitrary code on affected systems. The unspecified flaw in the JRE enables untrusted Java content, such as applets delivered through web browsers, to escape the sandbox and interact directly with the underlying operating system. CISA has confirmed active exploitation and flagged CVE-2013-0431 as associated with ransomware campaigns. With an EPSS percentile of 99.7%, this vulnerability is among the most frequently exploited in the entire CVE database.

KEV Information

Vendor
Oracle
Product
Java Runtime Environment (JRE)
Date Added
May 25, 2022
Due Date
June 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4

CWEs

Affected Products

VendorProductVersion
oraclejre1.7.0
oracleopenjdk7

References

Weakness Type

Since no specific CWE has been assigned to CVE-2013-0431, the underlying weakness type remains formally unspecified. The vulnerability is a sandbox bypass in the Java Runtime Environment that allows untrusted code to escape the JRE's security restrictions. This class of weakness involves a failure in the security manager or class loader mechanism to properly enforce the boundaries between trusted and untrusted code, enabling complete escape from the Java sandbox.

Impact Analysis

CVE-2013-0431 allows remote attackers to bypass the Java security sandbox entirely, granting untrusted code full access to the underlying operating system. This means an attacker can read and write files, execute arbitrary system commands, install malware, and establish persistent access to the compromised system. The vulnerability is remotely exploitable through the network, typically via web pages hosting malicious Java applets that execute when a user visits the page. The EPSS percentile of 99.7% reflects near-certain exploitation activity, and CISA's designation of a known ransomware association means this vulnerability has been directly used in ransomware attack chains. The combination of remote exploitability, no authentication requirements, and complete sandbox escape makes this a maximally impactful vulnerability for any system running a vulnerable JRE.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2013-0431 by including it in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 15, 2022. Critically, CISA has flagged this vulnerability as associated with ransomware campaigns, indicating direct use in ransomware attack chains. The EPSS percentile of 99.7% places it in the top 0.3% of all CVEs for exploitation likelihood. Java sandbox bypass vulnerabilities from 2012-2013 were among the most widely exploited attack vectors of the era, integrated into virtually every major exploit kit including Blackhole, Nuclear, and Angler, providing attackers with reliable drive-by download capabilities across millions of endpoints running the Java browser plugin.

Remediation

  1. Update the Oracle Java Runtime Environment to a version that addresses CVE-2013-0431. CISA's required action is to apply updates per vendor instructions.
  2. Remove the Java browser plugin from all endpoints immediately. Oracle has deprecated browser plugin support, and removal eliminates the primary attack vector for this and similar Java vulnerabilities.
  3. If Java is required for specific applications, deploy only the latest supported JRE/JDK version and restrict Java execution to approved, signed applications using deployment rule sets.
  4. Implement web content filtering and intrusion prevention systems to block the delivery of malicious Java applets and exploit kit landing pages.
  5. Monitor for indicators of compromise associated with Java-based exploitation, including unexpected child processes spawned by Java, outbound connections to known exploit kit infrastructure, and signs of ransomware deployment.

Technical Details

CVE-2013-0431 exploits an unspecified vulnerability in the Java Runtime Environment that allows complete bypass of the Java security sandbox. The JRE's security model relies on a sandbox mechanism that restricts untrusted code (such as web-delivered applets) from accessing local system resources, network services, and file system operations. This vulnerability defeats these restrictions entirely, allowing untrusted Java bytecode to execute with the full permissions of the Java process rather than within the constrained sandbox. The attack is delivered through crafted Java content, typically an applet loaded via a web page, that triggers the sandbox escape during execution by the JVM. Once the sandbox is bypassed, the attacker's code runs with the same permissions as the Java process itself, which on most systems means full user-level access to the operating system. This capability made the vulnerability extremely valuable for exploit kit operators who used it to deliver ransomware and other malware payloads through drive-by download attacks.

Frequently Asked Questions

Is CVE-2013-0431 being actively exploited?

Yes, CISA has confirmed active exploitation of CVE-2013-0431 and has flagged it as associated with ransomware campaigns. The EPSS percentile of 99.7% confirms it is among the most exploited CVEs in the database. It was widely integrated into exploit kits for drive-by download attacks.

What products are affected by CVE-2013-0431?

CVE-2013-0431 affects the Oracle Java Runtime Environment (JRE). All JRE versions prior to the security update that addressed this vulnerability are affected. The vulnerability is most dangerous on systems where the Java browser plugin was enabled, as it allows remote exploitation via crafted web pages.

How do I fix CVE-2013-0431?

Update to the latest supported version of the Oracle Java Runtime Environment and remove the Java browser plugin from all endpoints. If Java is needed for specific applications, restrict its execution to approved applications only and keep the JRE fully patched.

How severe is CVE-2013-0431?

CVE-2013-0431 is a critical sandbox bypass vulnerability with an EPSS percentile of 99.7% and a confirmed association with ransomware campaigns. The complete bypass of the Java security sandbox allows arbitrary code execution on affected systems, making it one of the most impactful Java vulnerabilities ever disclosed.

CVSS Score

5.3
MEDIUM(5.3)

EPSS Score

EPSS Score89.99%
EPSS Percentile99.8%

Dates

PublishedJanuary 31, 2013
Last ModifiedAugust 14, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.