Skip to main content

Alert: Apache Log4j vulnerabilities

The NCSC is advising organisations to take steps to mitigate the Apache Log4j vulnerabilities.

Art Alex via Getty Images

A number of vulnerabilities have been disclosed that affect multiple versions of Apache Log4j. Scanning and attempted exploitation has been detected globally, including in the UK. The NCSC is also aware of several cases where actors have exploited vulnerable instances of VMware Horizon, MobileIron and Ubiquiti Unifi Network Application (not an exhaustive list).

Proof-of-concept code has also been published for these vulnerabilities. 
 

Further reading

As well as the technical guidance provided in this Alert, the NCSC suggests further reading:
 




Updates:

 

(13/01/22): Information on cases of known exploited services added, latest version type removed 

(20/12/21): Alert re-structured - additional vulnerability detail added

(18/12/21): Addition of CVE-2021-45105, a Denial of Service in non-default configurations

(17/12/21): Upgrading of CVE-2021-45046 to a Remote Code Execution issue 

(16/12/21): Addition of exploitation information and addition of Windows search string 

(15/12/21): Minor updates to mitigation advice and information on CVE-2021-45046

(14/12/21): Minor updates to detection and mitigation advice following feedback

(13/12/21): Includes detection and enhanced mitigation advice

Published

News type

Alert