CVE-2021-44228: Log4j2 0-day Vulnerability
ID: 4717d113-4240-5e5c-a21b-8bd9fff4471f
STIX ID: report--4717d113-4240-5e5c-a21b-8bd9fff4471f
Feed Name: Zscaler Security Research Blog
Threat Score
**Apache Log4j (CVE-2021-44228) remote code execution advisory:** A critical RCE in Log4j versions 2.0-beta9 through 2.14.1 lets attackers trigger JNDI lookups to load remote code; Zscaler observed in‑the‑wild exploit attempts and urges immediate patching to 2.17.1 (or 2.12.2 for Java 7) or removal of the JndiLookup class, provides detection commands and vulnerable hashes, and has deployed signatures (Apache.Exploit.CVE-2021-44228) to block attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
