Apache disclosed CVE-2021-45105, a Log4j context-lookup vulnerability that could trigger a stack overflow and denial of service under specific conditions, adding to the remediation burden during the Log4Shell crisis. In December 2021, Apache recommended Log4j 2.17.0 for users running Java 8 or later to address the flaw; Log4j 1.x was reported unaffected by this specific vulnerability. The disclosure followed active exploitation of CVE-2021-44228, the earlier Log4Shell vulnerability, with Conti reportedly targeting VMware applications for lateral movement and Khonsari identified among early ransomware actors exploiting it.
The breadth of Log4j dependencies complicated mitigation: Google reported that more than 35,000 Java packages were affected by Log4Shell. CISA urged US federal agencies to patch immediately and report vulnerable infrastructure or applications, and issued Emergency Directive 22-02 to mitigate the Apache Log4j vulnerability; its directive page is now marked closed. The overlapping flaws underscored the need to inventory embedded and transitive Log4j dependencies, coordinate updates with application vendors, and investigate potentially exposed systems for exploitation rather than treating patch installation alone as evidence that a compromise had not occurred.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CVE-2021-45105 came to light following the earlier Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046. Under specific conditions, malicious input to context lookups can trigger a stack overflow and denial of service.
CISA advised US federal agencies to patch immediately and report information concerning vulnerable infrastructure or applications.
Google research found that more than 35,000 Java packages were impacted in some way by Log4j. The research highlighted difficulties in identifying dependencies between affected packages and applications.
Bleeping Computer reported that the Conti ransomware group was exploiting Log4Shell to attack VMware applications. The reported activity focused on internal networks and lateral movement during post-exploitation.
The Khonsari ransomware group was identified as being among the first actors to exploit CVE-2021-44228, also known as Log4Shell.
Apache Log4j 2.17.0 fixed CVE-2021-45105, and Apache recommended upgrading users running Java 8 or later. Apache also identified modifying context lookup functionality as a mitigation and stated that Log4j 1.x was unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.