问题
详细信息
点击展开
2021 年 12 月 10 日,ESET 开始研究 Log4j 2 实用程序中的漏洞(CVE-2021-44228)。该漏洞可能允许攻击者远程执行代码。
有关该漏洞的更多信息,请阅读我们的 WeLiveSecurity 文章。
- 缓解步骤:按照 WeLiveSecurity 文章Log4Shell 漏洞中的说明进行操作:我们目前了解到的情况。
- ESET Secure Authentication On-Prem (ESA) 用户:升级到 ESA On-Prem 3.0.40 或更高版本,或手动更新您的 Elasticsearch 实例。
- ESET Inspect 用户:在 ESET Inspect 中添加检测规则 以检测 Log4j 2。
解决方案
ESET 应用程序中的网络攻击保护可阻止尝试攻击
自 2021 年 12 月 11 日起,ESET Windows 安全应用程序中的 "网络攻击保护 "功能已更新,以检测对该漏洞的利用。从欧洲中部时间当日 14:24 起,ESET 已阻止尝试攻击。
以下 ESET 应用程序能够检测并阻止对您的系统或网络的潜在攻击:
- 商业应用程序:ESET Endpoint Antivirus、ESET Endpoint Security 和所有 ESET Server Security 产品。
- 家庭和小型办公室应用程序:ESET Internet Security、ESET Smart Security Premium、ESET Security Ultimate 和 ESET Small Business Security。
