CVE advisoryCRITICAL
CVE-2017-5645
Apache Log4j TCP UDP Socket Server Remote Code Execution
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in Apache Log4j's TCP and UDP socket servers allows for remote code execution via a crafted binary payload when deserializing logged events. This could lead to unauthorized access and control if these logging services are reachable.