Alert level

Exploit:Java/CVE-2013-0422

(?)

Encyclopedia entry
Updated: Feb 07, 2013  |  Published: Jan 11, 2013

Aliases
Not available

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection last updated:
Definition: 1.151.543.0
Released: May 21, 2013
Detection initially created:
Definition: 1.141.3699.0
Released: Jan 11, 2013


 

Summary

Exploit:Java/CVE-2013-0422 is a malicious Java applet that attempts to exploit a vulnerability (CVE-2013-0422) in the Java Runtime Environment (JRE), in order to download and install files of an attacker’s choice onto your computer.

If you visit a website containing the malicious code while using a vulnerable version of Java, the exploit is loaded. Note, however, that a number of legitimate websites could be compromised or unwillingly host a malicious applet through advertising frames which could redirect to or host a malicious Java applet.

Note: This detection may be triggered when you visit a website that contains the malicious code. Even if you are not using a vulnerable version of the JRE this detection may be reported when you visit a website that contains the malicious code. This does not mean that you have been compromised, rather that an attempt to compromise your computer has been made.

Additional cleaning and prevention steps

The nature of this threat means that you may need to take some steps to prevent being vulnerable from this, and similar exploits. We suggest you:

  1. Clear the Java cache
  2. Update Java
  3. Remove older versions of Java

For detailed information about these steps, please see the Additional removal instructions below.



 

Symptoms

If this detection is reported then it is likely that your computer has been compromised beyond this single infection. Your antivirus solution may soon begin to report other malware detections as new malicious files are downloaded and executed on your computer.

There are no common symptoms associated with this threat. Alert notifications from installed antivirus software may be the only symptoms.



 

Technical Information (Analysis)

Exploit:Java/CVE-2013-0422  is a malicious Java applet that attempts to exploit a vulnerability (CVE-2013-0422) in Oracle JRE 7.

If you visit a website containing the malicious code while using a vulnerable version of Java, the exploit is loaded. It then attempts to download and execute files from a remote host/URL; the files that are downloaded and executed could include additional malware.

Note: This detection may be triggered when you visit a website that contains the malicious code. Even if you are not using a vulnerable version of the JRE this detection may be reported when you visit a website that contains the malicious code. This does not mean that you have been compromised, rather that an attempt to compromise your computer has been made.

The first malware to exploit this vulnerability was found in December 2012 in the wild, and publicly disclosed in January 2013. It is exploiting a package restriction issue in JRE(Java Runtime Environment). The malware uses a typical Java exploitation technique by loading its malicious payload class in a trusted code area, which makes privilege escalation possible. The payload can be embedded in the JAR (Java Archive) file, or it may be downloaded from the Internet. The payload can be any kind of malware that the attacker wants to deliver to your computer.

Analysis by Jeong Wook (Matt) Oh



 

Prevention



 

Recovery

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

Additional removal instructions

A detection of this exploit may be triggered from your Java cache, if a previous attempt at exploit has been made. When using Java, the Java cache is known as the Temporary Files folder and is commonly located at C:\Users\<user name>\AppData\Local\Sun\Java\Deployment\cache\. The Temporary Files (or cache) folder contains webpage content that is stored on your hard disk for quick viewing.

We recommend that you delete your temporary Java files to prevent the persistent detection of this exploit from within this folder. For instructions on how to delete temporary Java files, please see the following article:

How do I clear the Java cache?

Update vulnerable Java applications

This threat exploits a known vulnerability in Java. After removing this threat, make sure that you install the updates available from the vendor. You can read more about this vulnerability in Java, as well as where to download the software update from the following links:

It may be necessary to remove older versions of Java that are still present. Keeping old and unsupported versions of Java on your system presents a serious security risk. To read more about why you should remove older versions of Java, see the following information.

Provide feedback