External risk intelligence

Apache Log4j TCP UDP Socket Server Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2017-5645

The vulnerability affects log4j when using specific TCP or UDP socket servers for logging. While these services are often internal components of an application stack rather than public-facing endpoints, they are networked services that can be exposed in some deployment configurations. Public exposure is possible but not the standard design pattern for logging socket servers.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Apache Log4j, a widely used Java logging library. The flaw allows for arbitrary code execution when specific network-based logging functionalities are enabled and receive specially crafted data, posing a significant risk to systems utilizing these features.

  • Flaw allows code execution via network logs.
  • Potentially affects many enterprise applications.
  • Confirm relevance and review for exposure.

Attack Path

How an attacker could exploit the issue

An attacker can target systems using Apache Log4j's TCP or UDP socket servers by sending a specially crafted binary payload. This payload, when processed by the deserialization function, can allow the attacker to execute arbitrary code on the affected system. This is possible because the logging component is exposed to network input and does not adequately validate the incoming data.

  • Network access to logging endpoints required.
  • Attacker sends a specially crafted payload.
  • Arbitrary code execution risk.

Live Threat

Current exploitation, exposure, and threat context

When Log4j's TCP or UDP socket servers are used to receive serialized log events, a malicious payload could be sent that, when deserialized, executes arbitrary code. This could impact systems that rely on these logging mechanisms for inter-application communication.

  • System data could be affected.
  • Networked logging services could be exploited.
  • Arbitrary code execution could occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects applications utilizing Apache Log4j with TCP or UDP socket servers for receiving serialized log events. Ownership typically falls to application or platform teams, who must first locate all instances of the affected Log4j component, assess their network reachability and criticality, and then engage vendor-specific remediation or mitigation strategies.

  • Identify accountable application owners.
  • Verify network exposure and asset criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Log4j and what is it used for?

Apache Log4j is a popular, widely used logging library for Java applications. It allows developers to record information about an application's operation, which is essential for troubleshooting and monitoring. Because of its flexibility, it is embedded into a vast range of enterprise software, including many products from vendors like Oracle, Red Hat, and NetApp, to manage internal system logs.

What is the vulnerability CWE-502 related to CVE-2017-5645?

This CVE involves a weakness known as CWE-502, which is Deserialization of Untrusted Data. Simply put, the software takes binary data received from a network connection and reconstructs it into an object without checking if it is safe. In this specific case, a specially crafted payload can trick the application into executing unauthorized code, essentially allowing a remote actor to control parts of the system by exploiting how Log4j handles serialized events.

How is this CVE-2017-5645 vulnerability triggered?

The flaw is triggered specifically when a Log4j application is configured to use a TCP or UDP socket server to receive log events. It does not affect standard file-based logging configurations. An attacker must be able to send a malicious, serialized binary payload to that specific open socket. If the application is not configured to accept these socket-based log connections, this specific attack path is not available.

Do I need to worry about my exposure to CVE-2017-5645?

Halo Surface Signal indicates that while these socket servers are often internal components, they are still network-accessible. You should care if your environment runs services using these specific Log4j socket configurations. While public exposure is not the standard design for these services, any deployment that allows external network access to these logging ports could be at risk.

How do I respond if I use affected technology?

The first step is to identify where your applications are utilizing Log4j's TCP or UDP socket server features. If you are using an affected version, you should look to update the Log4j library to a version that addresses this deserialization issue. Additionally, review your network and firewall configurations to ensure that these logging services are restricted and not inadvertently exposed to untrusted network traffic.

References