Log4j SocketServer Deserialization Remote Code Execution Vulnerability

Log4j SocketServer Deserialization Remote Code Execution Vulnerability

CVE-2019-17571 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Learn more about our Cis Benchmark Audit For Server Software.