Cybersecurity experts were left scrambling to patch the first Log4j vulnerability, CVE-2021-44228, before news broke on Tuesday that a new vulnerability, CVE 2021-45046, was discovered.
A new patch has now been released that seeks to address the fact that patch 2.15.0 was ” “incomplete in certain non-default configurations,” according to the CVE description.
The new vulnerability circumventated the first patch as the incomplete configurations allowed attackers “to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack,” the CVE description says.
The CVE says the new patch Log4j 2.16.0 fixes the problem by removing support for message lookup patterns and disabling JNDI functionality by default. It also notes that the issue can be mitigated in prior releases by removing the JndiLookup class from the classpath.
The vulnerability affects all versions of Log4j from 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 (the latest patch), and is scored 3.7 out of 10 on the CVSS rating system.
This morning, Check Point Research (CPR) gave an example of how a real attack works through this vulnerability.
While most detected miners leveraged it for Linux-based crypto mining, Check Point researchers have now detected a cyberattack involving an undetected, first time, NET-based malware.
This specific attack today targeted five victims in the finance, banking, and software industries in the Israel, United States, South Korea, Switzerland and Cyprus. The server that contains the malicious files is located in the US and hosts multiple malicious files.
Such attacks (crypto oriented and less destructive) represent the early stages of large scale attacks (such as ransomware). It is sort of a “live trial” of the vulnerability and the potential of the damage it can cause in laying the groundwork to later perform a larger offensive.
Recommended
- C-suite leaders must get on the same page on automation cybersecurity
- Strathclyde Uni spin-out Lupovis secures £615k tech research funding
- Further growth for Scots welltech Frog Systems after four new hires
Once any type of malware is injected, it’s only a “question of time for a larger attack,” according to CPR.
Currently, CPR has tracked over 1,272,000 attempts to exploit the vulnerability, affecting over 44% of corporate networks globally.
Speaking about Log4j, Lotem Finkelstein, Head of Threat Intelligence at Check Point Software, said: “Unlike other major cyber attacks that involve one or limited number of software, Log4j is basically embedded in every Java based product or web service. It is very difficult to manually remediate it.
“Once an exploration was published (on Friday), scans of the internet ensued (to allocate surfaces which are vulnerable due to this incident). Those who won’t implement a protection are probably already scanned by malicious actors. Already, we’ve documented over 1,272,000 attacks, where over 44% of corporate networks globally have been targeted.
“This vulnerability, because of the complexity in patching it and easiness to exploit, will stay with us for years to come, unless companies and services take immediate action to prevent the attacks on their products by implementing a protection.”





