Skip to main content
Skip to main content
Microsoft Security Intelligence
8 entries found.
Updated on Jan 11, 2013

Windows Defender detects and removes this threat.

This threat uses a Java vulnerability to download and run files on your PC, including other malware.

It runs when you visit a hacked or malicious website and you have a vulnerable version of Java.

The following versions of Java are vulnerable:

  • Java Development Kit and Java Runtime Environment 7 Update 10 and earlier

To check if you're running a vulnerable version of Java:

  1. In Control Panel, double-click Programs.
  2. If Java is installed you will see it in the list of installed programs. Click it to open the Java Control Panel.
  3. On the General tab, click About to see which version of Java you have installed.

You may get an alert about this threat even if you're not using a vulnerable version of Java. This is because we detect when a website tries to use the vulnerability, even if it isn't successful.

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Jan 11, 2013

Exploit:Java/CVE-2013-0422.B is a variant of the Exploit:Java/CVE-2013-0422 family of exploits; malicious Java applets that attempt to exploit a vulnerability (CVE-2013-0422) the Java Runtime Environment (JRE), in order to download and install files of an attacker’s choice onto your computer.

If you visit a website containing the malicious code while using a vulnerable version of Java, the exploit is loaded. Note, however, that a number of legitimate websites could be compromised or unwillingly host a malicious applet through advertising frames which could redirect to or host a malicious Java applet.

Update vulnerable Java applications

This threat exploits a known vulnerability in Java. After removing this threat, make sure that you install the updates available from the vendor. You can read more about this vulnerability in Java, as well as where to download the software update from the following links:

It may be necessary to remove older versions of Java that are still present. Keeping old and unsupported versions of Java on your system presents a serious security risk. To read more about why you should remove older versions of Java, see the following information.

Alert level: severe
Updated on Jan 11, 2013
Alert level: severe
Updated on Jan 31, 2013
Alert level: severe
Updated on Feb 26, 2016
Alert level: severe
Updated on Jan 14, 2013
Alert level: severe
Updated on Jan 23, 2013
Alert level: severe
Updated on Feb 23, 2016
Alert level: severe