{"id":21230,"date":"2013-01-14T12:47:11","date_gmt":"2013-01-14T20:47:11","guid":{"rendered":"http:\/\/blogs.mcafee.com\/?p=21230"},"modified":"2025-06-02T03:07:46","modified_gmt":"2025-06-02T10:07:46","slug":"java-zero-day-vulnerability-pushes-out-crimeware","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/","title":{"rendered":"Java Zero-Day Vulnerability Pushes Out Crimeware"},"content":{"rendered":"<p><strong>This blog was updated on January 14. See the end of the file.<\/strong><\/p>\n<p>A new Java zero-day vulnerability is spreading malicious files to infect unprotected users. The threat is dangerous: Just browsing a malicious page or clicking a malicious link in spam is enough to cause an infection when combined with a vulnerable Java version.<\/p>\n<p>Because most browsers enable Java by default, this vulnerability can be used by attackers to easily spread malwares using various exploit kits available in the market.<\/p>\n<h2><strong>Exploit Analysis<\/strong><\/h2>\n<p>The vulnerability is triggered by abusing restricted package permissions, which makes it possible for untrusted code to get access to classes that are part of restricted packages. Hence this can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.<\/p>\n<p>This vulnerability in Java is very similar in characteristics to Exploit CVE2012-4681<a href=\"https:\/\/kc.mcafee.com\/resources\/sites\/MCAFEE\/content\/live\/PRODUCT_DOCUMENTATION\/24000\/PD24040\/en_US\/McAfee_Labs_Threat_Advisory_Exploit_CVE2012_4681.pdf\">,<\/a> though not completely similar to it.<\/p>\n<p>Generally, the Java Virtual Machine first checks the privilege\/permission of the class file or object before allowing it to execute in the Java applet sandbox environment. Any applet that does not have the required credentials will not execute. The goal of attackers is to exploit this vulnerability in order to escalate privileges, which enable the Java applet code to run outside the sandbox.<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/attachment\/0-day1\" rel=\"attachment wp-att-21234\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-21234\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg\" alt=\"\" width=\"583\" height=\"523\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-Day1.jpg 583w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-Day1-300x269.jpg 300w\" sizes=\"auto, (max-width: 583px) 100vw, 583px\" \/><\/a>Figure 1: A typical vulnerability flow for this Java zero-day attack.<\/p>\n<p>As shown in the preceding image, the victim first visits a compromised website link, which in turn loads the malicious Java applet in the vulnerable Java environment and executes the downloaded malicious payload on the compromised user system.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/attachment\/0-day2\" rel=\"attachment wp-att-21235\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-21235\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-day2.jpg\" alt=\"\" width=\"632\" height=\"408\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-day2.jpg 632w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-day2-300x193.jpg 300w\" sizes=\"auto, (max-width: 632px) 100vw, 632px\" \/><\/a>Figure 2: The main exploit code.<\/p>\n<p>The preceding image shows how the attack works. It exploits the vulnerability using &#8220;MBeanInstantiator,&#8221; which allows the loading of a restricted class by exploiting the \u201cfindClass\u201d method of the \u201ccom.sun.jmx.mbeanserver.MBeanInstantiator\u201d class. By doing this, we can retrieve the class references of any package.<\/p>\n<h2><b>Steps in exploiting the vulnerability:<\/b><\/h2>\n<ol>\n<li>First the call to the vulnerable \u201ccom.sun.jmx.mbeanserver.MBeanInstantiator.findClass\u201d is made<\/li>\n<li>This will then call the \u201cLoadClass\u201d and \u201cClass.forName,\u201d which allow us to load any package in any classes available<\/li>\n<li>However, the \u201cMBeanInstantiator\u201d constructor is a private member. First, it has to get a reference to an instance of this object so that it can be used to load a class to be used later.<\/li>\n<li>This is achieved by calling a public static method, which in turn returns the \u201ccom.sun.jmx.mbeanserver.JmxMBeanServer\u201d instance.<\/li>\n<li>The \u201cJmxMBeanServer\u201d class has a public method called \u201cgetMBeanInstantiator\u201d [Figure 3], which returns the \u201cMBeanInstantiator\u201d instance. Using this we can find any class that we require using the \u201cfindClass\u201d method.<\/li>\n<li>Then, the attack uses the new reflection API to obtain and call MethodHandle objects [Figure 4].<\/li>\n<li>This MethodHandle point to methods and constructors of restricted classes that were retrieved earlier, as mentioned above. This is achieved by the \u201cinvokeWithArguments\u201d method call of java.lang.invoke.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/attachment\/0-day3\" rel=\"attachment wp-att-21232\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-21232\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-day3.jpg\" alt=\"\" width=\"632\" height=\"475\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-day3.jpg 632w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-day3-300x225.jpg 300w\" sizes=\"auto, (max-width: 632px) 100vw, 632px\" \/><\/a><\/p>\n<p align=\"center\">Figure 3: A JmxMBeanServer code snippet.<\/p>\n<p style=\"text-align: left;\" align=\"center\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/attachment\/0-day4\" rel=\"attachment wp-att-21233\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-21233\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-day4.jpg\" alt=\"\" width=\"683\" height=\"346\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-day4.jpg 683w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-day4-300x151.jpg 300w\" sizes=\"auto, (max-width: 683px) 100vw, 683px\" \/><\/a><\/p>\n<p align=\"center\">Figure 4:\u00a0 The attack uses the new reflection API.<\/p>\n<h2><b>Affected Java Versions<\/b><\/h2>\n<p>This exploit targets the vulnerability in Java Version 7 Update 10 and earlier.<\/p>\n<p>An initial threat vector may be hosted on a compromised website in the form of an applet that contains code to exploit this vulnerability. The intent of the exploit is to surreptitiously download and execute additional malware on the infected system. An indication of this may be the presence of unusual traffic to unknown domains.<\/p>\n<h2><b>Exploit Kit Seizes the Opportunity<\/b><\/h2>\n<p>In our analysis, we have seen this vulnerability use various exploit kits, including Blackhole, <a href=\"https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/red-kit-an-emerging-exploit-pack\">Red Kit<\/a>, Cool, Nuclear, and Sakura. These exploit kits appear to push out PWS-Zbot, ransomware, and ZeroAccess as payloads.<\/p>\n<p>McAfee products detect this malware in our latest DATs as <a href=\"http:\/\/home.mcafee.com\/VirusInfo\/VirusProfile.aspx?key=1628498\">Exploit CVE2013-0422<\/a>.<\/p>\n<h2><b>Mitigation<\/b><\/h2>\n<p>Because this is a zero-day attack there is no patch yet for the vulnerability. Hence our recommendation is to completely disable Java until the patch for this vulnerability is released.<\/p>\n<p>If you cannot disable Java, you can take any of the following steps:<\/p>\n<ul>\n<li>In the Java Control panel under the Security tab, set the security level to &#8220;Very High.&#8221; By doing this, unsigned (sandboxed) apps and local applets will not run.<\/li>\n<li>Keep your McAfee antimalware definitions updated. We detect this attack as Exploit CVE2013-0422 as well as the payloads it downloads.<\/li>\n<\/ul>\n<p>Meanwhile, we will continue to monitor this threat closely for new malware payloads and update that information here.<\/p>\n<p><strong>Update, January 14<\/strong><\/p>\n<p>Oracle has released patch for this vulnerability that is available <a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/alert-cve-2013-0422-1896849.html#PatchTable\">here<\/a>. Java users should update their software immediately.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading&#8230;<\/p>\n","protected":false},"author":695,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[180,3947],"coauthors":[1477],"class_list":["post-21230","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-malware","tag-virtualization"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Java Zero-Day Vulnerability Pushes Out Crimeware | McAfee Blog<\/title>\n<meta name=\"description\" content=\"This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Java Zero-Day Vulnerability Pushes Out Crimeware | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2013-01-14T20:47:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-02T10:07:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-Day1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"583\" \/>\n\t<meta property=\"og:image:height\" content=\"523\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"McAfee Labs\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee_Labs\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee Labs\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/\"},\"author\":{\"name\":\"McAfee Labs\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad\"},\"headline\":\"Java Zero-Day Vulnerability Pushes Out Crimeware\",\"datePublished\":\"2013-01-14T20:47:11+00:00\",\"dateModified\":\"2025-06-02T10:07:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/\"},\"wordCount\":746,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg\",\"keywords\":[\"malware\",\"virtualization\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/\",\"name\":\"Java Zero-Day Vulnerability Pushes Out Crimeware | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg\",\"datePublished\":\"2013-01-14T20:47:11+00:00\",\"dateModified\":\"2025-06-02T10:07:46+00:00\",\"description\":\"This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage\",\"url\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg\",\"contentUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Java Zero-Day Vulnerability Pushes Out Crimeware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad\",\"name\":\"McAfee Labs\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/af947d76ffbef8521094b476cf8050c3\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg\",\"caption\":\"McAfee Labs\"},\"description\":\"McAfee Labs is one of the leading sources for threat research, threat intelligence, and cybersecurity thought leadership. See our blog posts below for more information.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee_Labs\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee-labs\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Java Zero-Day Vulnerability Pushes Out Crimeware | McAfee Blog","description":"This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Java Zero-Day Vulnerability Pushes Out Crimeware | McAfee Blog","og_description":"This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users.","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2013-01-14T20:47:11+00:00","article_modified_time":"2025-06-02T10:07:46+00:00","og_image":[{"width":583,"height":523,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2013\/01\/0-Day1.jpg","type":"image\/jpeg"}],"author":"McAfee Labs","twitter_card":"summary_large_image","twitter_creator":"@McAfee_Labs","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee Labs","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/"},"author":{"name":"McAfee Labs","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad"},"headline":"Java Zero-Day Vulnerability Pushes Out Crimeware","datePublished":"2013-01-14T20:47:11+00:00","dateModified":"2025-06-02T10:07:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/"},"wordCount":746,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg","keywords":["malware","virtualization"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/","name":"Java Zero-Day Vulnerability Pushes Out Crimeware | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg","datePublished":"2013-01-14T20:47:11+00:00","dateModified":"2025-06-02T10:07:46+00:00","description":"This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users.","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#primaryimage","url":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg","contentUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2013\/01\/0-Day1.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/java-zero-day-vulnerability-pushes-out-crimeware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"Java Zero-Day Vulnerability Pushes Out Crimeware"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad","name":"McAfee Labs","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/af947d76ffbef8521094b476cf8050c3","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg","caption":"McAfee Labs"},"description":"McAfee Labs is one of the leading sources for threat research, threat intelligence, and cybersecurity thought leadership. See our blog posts below for more information.","sameAs":["https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee_Labs"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee-labs\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/21230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/695"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=21230"}],"version-history":[{"count":2,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/21230\/revisions"}],"predecessor-version":[{"id":214835,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/21230\/revisions\/214835"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=21230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=21230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=21230"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=21230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}