CISA issues emergency directive to fix Log4j vulnerability

Federal agencies have a week to get their systems patched

The US government's Cybersecurity and Infrastructure Security Agency (CISA) on Friday escalated its call to fix the Apache Log4j vulnerability with an emergency directive requiring federal agencies to take corrective action by 5 pm EST on December 23, 2021.

Log4j is a Java-based open source logging library used in millions of applications. Versions up to and including 2.14.1 contain a critical remote code execution flaw (CVE-2021-44228), and the fix incorporated into version 2.15, released a week ago, has since been bypassed.

The software library includes a text-formatting language that allows code execution and the vulnerability enables a remote attacker to craft a string like ${jndi:ldap://} to fetch the referenced object on the specified server and execute it.

The flaw, referred to as Log4Shell or Logjam, is rated Critical – with a CVSS score of 10.0 – and is already being actively exploited, hence the hullabaloo.

"Since Log4Shell is a critical flaw with a huge attack surface and is very simple to exploit, threat actors are actively using it to launch their attacks even with a patch already released, said Felipe Tarijon, a malware analyst at Appgate, in an email to The Register. "Several state-sponsored groups are exploiting the flaw in the wild and making modifications to the Log4j exploit."

Tarijon said botnets Muhstik and a Mirai-variant were abusing the flaw on Linux devices before public disclosure, and exploitation activities like the deployment of cryptocurrency miners have been observed. He added that a new ransomware family targeting Windows named Khonsari has been seen exploiting the Log4j vulnerability, which has also been used to deliver the Orcus Remote Access Trojan.

"This vulnerability, which is being widely exploited by a growing set of threat actors, presents an urgent challenge to network defenders given its broad use," said CISA Director Jen Easterly in a statement last week. "End users will be reliant on their vendors, and the vendor community must immediately identify, mitigate, and patch the wide array of products using this software."

CISA earlier this week published mitigation guidance directing federal civilian agencies to update Log4j to version 2.15 by December 24, 2021, to address CVE-2021-44228.

But on Wednesday that advice was superseded with the recommendation that affected entities update to version 2.16, released two days earlier to address a mitigation bypass and a separate flaw that had been identified, CVE-2021-45046, that allows an attacker to conduct a denial-of-service attack on affected devices via malicious payloads.

The emergency directive requires federal civilian agencies by the end of the business day on December 23rd to: 1) Identify all systems that accept data over the internet; to check those systems against the CISA-managed GitHub repository; apply the latest Log4j patch if appropriate or take vulnerable systems offline; submit a pull request identifying assets not referenced; and assume that vulnerable systems have been compromised, with the post-incident investigation and mitigation that entails.

And by 5 pm EST on December 28, 2021, agencies are required to report systems they identified during this process and to detail whatever action was taken.

The fire drill, however, may not be over yet. The volunteer maintainers of Log4j have identified an infinite recursion bug, affecting versions up through 2.16, that apparently will crash the application if string substitution is attempted on this string pattern ${${::-${::-$${::-j}}}}.

As this article was filed, there's not yet public agreement about whether this constitutes a meaningful denial-of-service attack risk or about whether a CVE will be sought for the issue. Stay tuned.

"The first patch (2.15) still has a vulnerability in non-default configurations allowing exfiltration of sensitive data," said Tarijon in an email to The Register. "So, applying the latest patch by updating to 2.16 would be enough to fix the remote code execution (RCE) problem. It disables JNDI, the component abused to leverage the RCE.

The recursion bug in version 2.16, he said, appears to be less critical because it can only be used for a denial of service attack that crashes the log system. Though the RCE bug has been patched in 2.16, he expects it will continue to have a significant impact because of the huge attack surface that depends upon vendors and third parties who may not apply patches quickly enough.

"As a reference, the PrintSpooler vulnerabilities in July of this year led to an RCE bug, patched by Microsoft, but subsequent exploits and variants appeared later as soon as threat actors started to abuse the vulnerability in the wild," Tarijon explained.

In other words, expect to keep hearing about Log4j. ®

Broader topics

Other stories you might like

  • How ICE became a $2.8b domestic surveillance agency
    Your US tax dollars at work

    The US Immigration and Customs Enforcement (ICE) agency has spent about $2.8 billion over the past 14 years on a massive surveillance "dragnet" that uses big data and facial-recognition technology to secretly spy on most Americans, according to a report from Georgetown Law's Center on Privacy and Technology.

    The research took two years and included "hundreds" of Freedom of Information Act requests, along with reviews of ICE's contracting and procurement records. It details how ICE surveillance spending jumped from about $71 million annually in 2008 to about $388 million per year as of 2021. The network it has purchased with this $2.8 billion means that "ICE now operates as a domestic surveillance agency" and its methods cross "legal and ethical lines," the report concludes.

    ICE did not respond to The Register's request for comment.

    Continue reading
  • Fully automated AI networks less than 5 years away, reckons Juniper CEO
    You robot kids, get off my LAN

    AI will completely automate the network within five years, Juniper CEO Rami Rahim boasted during the company’s Global Summit this week.

    “I truly believe that just as there is this need today for a self-driving automobile, the future is around a self-driving network where humans literally have to do nothing,” he said. “It's probably weird for people to hear the CEO of a networking company say that… but that's exactly what we should be wishing for.”

    Rahim believes AI-driven automation is the latest phase in computer networking’s evolution, which began with the rise of TCP/IP and the internet, was accelerated by faster and more efficient silicon, and then made manageable by advances in software.

    Continue reading
  • Pictured: Sagittarius A*, the supermassive black hole at the center of the Milky Way
    We speak to scientists involved in historic first snap – and no, this isn't the M87*

    Astronomers have captured a clear image of the gigantic supermassive black hole at the center of our galaxy for the first time.

    Sagittarius A*, or Sgr A* for short, is 27,000 light-years from Earth. Scientists knew for a while there was a mysterious object in the constellation of Sagittarius emitting strong radio waves, though it wasn't really discovered until the 1970s. Although astronomers managed to characterize some of the object's properties, experts weren't quite sure what exactly they were looking at.

    Years later, in 2020, the Nobel Prize in physics was awarded to a pair of scientists, who mathematically proved the object must be a supermassive black hole. Now, their work has been experimentally verified in the form of the first-ever snap of Sgr A*, captured by more than 300 researchers working across 80 institutions in the Event Horizon Telescope Collaboration. 

    Continue reading
  • Shopping for malware: $260 gets you a password stealer. $90 for a crypto-miner...
    We take a look at low, low subscription prices – not that we want to give anyone any ideas

    A Tor-hidden website dubbed the Eternity Project is offering a toolkit of malware, including ransomware, worms, and – coming soon – distributed denial-of-service programs, at low prices.

    According to researchers at cyber-intelligence outfit Cyble, the Eternity site's operators also have a channel on Telegram, where they provide videos detailing features and functions of the Windows malware. Once bought, it's up to the buyer how victims' computers are infected; we'll leave that to your imagination.

    The Telegram channel has about 500 subscribers, Team Cyble documented this week. Once someone decides to purchase of one or more of Eternity's malware components, they have the option to customize the final binary executable for whatever crimes they want to commit.

    Continue reading
  • Ukrainian crook jailed in US for selling thousands of stolen login credentials
    Touting info on 6,700 compromised systems will get you four years behind bars

    A Ukrainian man has been sentenced to four years in a US federal prison for selling on a dark-web marketplace stolen login credentials for more than 6,700 compromised servers.

    Glib Oleksandr Ivanov-Tolpintsev, 28, was arrested by Polish authorities in Korczowa, Poland, on October 3, 2020, and extradited to America. He pleaded guilty on February 22, and was sentenced on Thursday in a Florida federal district court. The court also ordered Ivanov-Tolpintsev, of Chernivtsi, Ukraine, to forfeit his ill-gotten gains of $82,648 from the credential theft scheme.

    The prosecution's documents [PDF] detail an unnamed, dark-web marketplace on which usernames and passwords along with personal data, including more than 330,000 dates of birth and social security numbers belonging to US residents, were bought and sold illegally.

    Continue reading

Biting the hand that feeds IT © 1998–2022