[KB8254] Information regarding the Log4j 2 vulnerability

Issue

Details


Click to expand

On December 10th, 2021, ESET began researching a vulnerability in the Log4j 2 utility (CVE-2021-44228). This vulnerability may allow an attacker to execute code remotely.

For more information about the vulnerability, read our WeLiveSecurity article.


Solution

Log4j 2 vulnerability in ESET applications

No supported ESET applications are affected by the Log4j 2 vulnerability.

Network Attack Protection in ESET applications blocks attempted attacks

As of December 11th, 2021, the Network Attack Protection feature in ESET security applications for Windows was updated to detect exploits of the vulnerability. ESET has been blocking attempted attacks from 14:24 CET the same day.

The following ESET applications are able to detect and block a potential attack on your system or network:

  • Business applications: ESET Endpoint Antivirus, ESET Endpoint Security and all ESET Server Security products.
  • Home and small office applications: ESET Internet Security, ESET Smart Security Premium, ESET Security Ultimate and ESET Small Business Security.