Critical RCE Vulnerability in Log4J2
ID: e0f303ec-4f29-5eac-84f8-105559150917
STIX ID: report--e0f303ec-4f29-5eac-84f8-105559150917
Feed Name: WatchGuard Secplicity Blog
WatchGuard Threat Lab reports on CVE-2021-44228, a critical (CVSS 10.0) unauthenticated RCE in Apache Log4j2 that abuses JNDI lookups to fetch and execute attacker-controlled code. The bulletin notes active exploitation observed against services that log attacker-controlled strings (e.g., HTTP User-Agent), including attempts to deploy a cryptominer, and provides immediate mitigations (upgrade to Log4j 2.15.0, set log4j2.formatMsgNoLookups=true, JVM-specific mitigations) along with product impact and IPS signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
