logo

Analysis of Log4Shell vulnerability & CVE-2021-45046

ID: 1d99b4c8-4cf8-5d30-b5b4-c36984992689

STIX ID: report--1d99b4c8-4cf8-5d30-b5b4-c36984992689

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2022-11-30

Date Updated: 2026-04-27

...
...

Elastic Security details its detection and response to the Log4Shell vulnerability (CVE-2021-44228) and the related CVE-2021-45046, reporting active exploitation and widespread adoption by threat actors. The advisory documents observed deployments of multiple malware families (including crypto-miners), expanded detections and hunting queries, notes CVE-2021-45046 was re-scored to CVSS 9.0 with proof-of-concept activity, and recommends upgrading Log4j or removing the JndiLookup class while providing resources and guidance to users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.