Issue
Details
Click to expand
On December 10th, 2021, ESET began researching a vulnerability in the Log4j 2 utility (CVE-2021-44228). This vulnerability may allow an attacker to execute code remotely.
For more information about the vulnerability, read our WeLiveSecurity article.
- Mitigation steps: Follow the instructions in the WeLiveSecurity article Log4Shell vulnerability: What we know so far.
- ESET Secure Authentication On-Prem (ESA) users: Upgrade to ESA On-Prem version 3.0.40 or later or manually update your Elasticsearch instance.
- ESET Inspect users: Add detection rules in ESET Inspect to detect Log4j 2.
Solution
Network Attack Protection in ESET applications blocks attempted attacks
As of December 11th, 2021, the Network Attack Protection feature in ESET security applications for Windows was updated to detect exploits of the vulnerability. ESET has been blocking attempted attacks from 14:24 CET the same day.
The following ESET applications are able to detect and block a potential attack on your system or network:
- Business applications: ESET Endpoint Antivirus, ESET Endpoint Security and all ESET Server Security products.
- Home and small office applications: ESET Internet Security, ESET Smart Security Premium, ESET Security Ultimate and ESET Small Business Security.
