New Warning on Log4j from Microsoft!
Microsoft made an extra warning on January 3, 2022 on the page where it published detailed information about log4j.
As the world is ravaged by the log4j vulnerability, Microsoft has released a new information update for Windows and Azure customers. Here is the update:
The Log4j vulnerabilities represent a complex and high-risk situation for companies across the globe. This open-source component is widely used across many suppliers’ software and services. By nature of Log4j being a component, the vulnerabilities affect not only applications that use vulnerable libraries, but also any services that use these applications, so customers may not readily know how widespread the issue is in their environment. Customers are encouraged to utilize scripts and scanning tools to assess their risk and impact. Microsoft has observed attackers using many of the same inventory techniques to locate targets. Sophisticated adversaries (like nation-state actors) and commodity attackers alike have been observed taking advantage of these vulnerabilities. There is high potential for the expanded use of the vulnerabilities.
Exploitation attempts and testing have remained high during the last weeks of December. We have observed many existing attackers adding exploits of these vulnerabilities in their existing malware kits and tactics, from coin miners to hands-on-keyboard attacks. Organizations may not realize their environments may already be compromised. Microsoft recommends customers to do additional review of devices where vulnerable installations are discovered. At this juncture, customers should assume broad availability of exploit code and scanning capabilities to be a real and present danger to their environments. Due to the many software and services that are impacted and given the pace of updates, this is expected to have a long tail for remediation, requiring ongoing, sustainable vigilance.
Related Articles:
- 4 Practical Strategies for Log4j Discovery
- What Every Business Should Know About Log4Shell
- NVIDIA, HPE Products Affected by Log4j Vulnerabilities
Sign up for the e-mail list to be informed about the developments in the cyber world and to be informed about the weekly newsletter.