CVE-2013-1491 is a remote code execution vulnerability in the 2D component of Oracle Java SE, affecting JRE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier. The vulnerability allows remote attackers to execute arbitrary code via crafted Java Web Start applications or applets, exploiting flaws in the 2D subcomponent. The issue was demonstrated by Joshua Drake at Pwn2Own 2013.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for CVE-2013-1491, a memory corruption vulnerability in Oracle Java SE 7u17, leveraging the Java JIT-spray technique. The exploit targets Windows 7 32-bit systems running JRE 7u17 and is delivered via a Java applet embedded in an HTML file (HelloApplet.html). The main exploit logic resides in Exploit.java, which performs JIT spraying by dynamically loading many classes to manipulate memory layout, and then triggers the vulnerability to execute embedded shellcode. The shellcode, provided in shellcode-xp.txt and encoded as a Unicode string in Java, launches calc.exe as a demonstration of code execution. The repository includes Python scripts (gen.py, copy.py) to automate the generation and compilation of the required Java classes for the spray, as well as a batch script (make.bat) to build the exploit. The exploit demonstrates advanced exploitation techniques but is a PoC and not weaponized for broad use. No network endpoints or external IPs are hardcoded; the attack vector is browser-based via a malicious Java applet.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.