12/30/2021
Apache Log4J Briefing
Paradigm Software L.L.C., (PSLLC) constantly monitors emerging threats in software and technology. A vulnerability in an Apache logging utility known as “Log4J” was discovered on Thursday, December 9th. The scope and potential impact of this vulnerability is significant and concerning.
Upon the news of this exploit, PSLLC immediately began reviewing and scanning for exposure to this vulnerability. PSLLC is happy to announce that, upon conclusion of our review, we found no internal usages or vulnerabilities from Log4J.
We have also reached out to third-party vendors we integrate with to confirm that no third parties are impacted by this exploit. We encourage clients to use Microsoft’s Log4J Guidance to review their systems for any potential exposure to this threat: Guidance for preventing, detecting, and hunting for CVE-2021-44228 Log4j 2 exploitation - Microsoft Security Blog
https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
PSLLC will continue to monitor this and other threats and keep our clients updated.
Microsoft is tracking threats taking advantage of the CVE-2021-44228 remote code ex*****on (RCE) vulnerability in Apache Log4j 2. Get technical info and guidance for using Microsoft security solutions to protect against attacks.