CVE-2013-2423

LOW(3.7)KEVLikely Exploited

Oracle JRE Unspecified Vulnerability

Description

CVE-2013-2423 is a vulnerability in the HotSpot component of the Oracle Java Runtime Environment (JRE) that allows remote attackers to affect the integrity of the system. The unspecified flaw enables remote exploitation through crafted Java content, potentially allowing attackers to modify data or execute unauthorized actions on systems running vulnerable JRE versions. CISA has confirmed active exploitation by including CVE-2013-2423 in the Known Exploited Vulnerabilities catalog. With an EPSS percentile of 99.8%, this vulnerability ranks among the most actively exploited in the entire CVE database, reflecting the widespread targeting of Java runtime environments by threat actors.

KEV Information

Vendor
Oracle
Product
Java Runtime Environment (JRE)
Date Added
May 25, 2022
Due Date
June 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4

CWEs

Affected Products

VendorProductVersion
oraclejre1.7.0
canonicalubuntu linux12.10
opensuseopensuse12.3

References

Weakness Type

Since no specific CWE has been assigned to CVE-2013-2423, the underlying weakness type remains formally unspecified. The vulnerability resides in the HotSpot component of the JRE, which is the core execution engine responsible for compiling and executing Java bytecode. Flaws in HotSpot can compromise the JVM's security enforcement, allowing untrusted code to bypass intended restrictions and affect system integrity.

Impact Analysis

CVE-2013-2423 allows remote attackers to affect the integrity of systems running the vulnerable Java Runtime Environment through crafted Java content delivered via web browsers or other Java-enabled applications. The vulnerability specifically targets the HotSpot execution engine, and exploitation can allow an attacker to bypass Java's security sandbox and modify system data or execute unauthorized operations. While the primary impact is on integrity, a successful sandbox escape in the JRE can provide a foundation for further exploitation including code execution. The EPSS percentile of 99.8% places this vulnerability in the top 0.2% of all CVEs for exploitation likelihood, reflecting the massive attack surface presented by Java's ubiquitous deployment in enterprise environments, particularly through web browser plugins that were common during the 2013 era.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2013-2423 by including it in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 15, 2022. The EPSS percentile of 99.8% makes this one of the most exploited CVEs in the entire database, reflecting its integration into multiple exploit kits and attack frameworks. Java vulnerabilities from this era were among the most commonly exploited attack vectors, as the Java browser plugin was widely deployed and provided a reliable path for drive-by download attacks. The HotSpot component vulnerability was particularly valuable to attackers as it affects the core execution engine of the JVM.

Remediation

  1. Update the Oracle Java Runtime Environment to a version that addresses CVE-2013-2423. CISA's required action is to apply updates per vendor instructions.
  2. Remove the Java browser plugin entirely from all endpoints, as Oracle has deprecated and removed browser plugin support in modern Java versions. This eliminates the primary web-based attack vector.
  3. If Java is required for specific applications, deploy only the latest supported JRE/JDK version and restrict Java execution to approved applications using deployment rule sets or application whitelisting.
  4. Implement network-level controls to block the delivery of malicious Java applets and web content targeting Java vulnerabilities through web proxy filtering and intrusion prevention systems.
  5. Monitor endpoints for Java-related exploit activity, including unexpected Java process behavior, network connections initiated by Java processes, and attempts to load unsigned or untrusted Java code.

Technical Details

CVE-2013-2423 targets the HotSpot component of the Oracle Java Runtime Environment, which serves as the JVM's execution engine responsible for just-in-time (JIT) compilation and bytecode interpretation. The unspecified vulnerability allows remote attackers to affect system integrity by exploiting a flaw in how HotSpot processes certain Java operations. In the JRE security model, untrusted code (such as applets loaded from the web) is supposed to execute within a restricted sandbox that prevents access to local system resources. A flaw in HotSpot can break these security guarantees by allowing untrusted bytecode to perform operations that should be restricted, such as modifying memory, accessing restricted APIs, or influencing the JIT compilation process to generate code that bypasses security checks. The attack vector is network-based, delivered through crafted Java content that triggers the vulnerability when processed by the HotSpot engine.

Frequently Asked Questions

Is CVE-2013-2423 being actively exploited?

Yes, CISA has confirmed active exploitation of CVE-2013-2423 and added it to the Known Exploited Vulnerabilities (KEV) catalog. The EPSS percentile of 99.8% places it among the most actively exploited CVEs in the database. It was widely incorporated into exploit kits targeting Java browser plugins.

What products are affected by CVE-2013-2423?

CVE-2013-2423 affects the Oracle Java Runtime Environment (JRE), specifically the HotSpot component. All JRE versions prior to the security update that addressed this vulnerability are affected. The vulnerability is particularly relevant on systems where the Java browser plugin was enabled.

How do I fix CVE-2013-2423?

Update to the latest supported version of the Oracle Java Runtime Environment. Remove the Java browser plugin from all endpoints, as it has been deprecated. If Java is required for specific applications, restrict its use through deployment rule sets and application whitelisting.

How severe is CVE-2013-2423?

CVE-2013-2423 has an EPSS percentile of 99.8%, making it one of the most exploited vulnerabilities in existence. Its inclusion in the CISA KEV catalog confirms sustained real-world exploitation. The vulnerability allows attackers to affect system integrity through the Java HotSpot engine, with potential for further exploitation through sandbox escape.

CVSS Score

3.7
LOW(3.7)

EPSS Score

EPSS Score85.33%
EPSS Percentile99.7%

Dates

PublishedApril 17, 2013
Last ModifiedJune 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.