John Anthony Smith: A Software Vulnerability Causing Havoc The World Over

  • Thursday, December 23, 2021
  • John Anthony Smith
John Anthony Smith
John Anthony Smith

A software service, Log4j, that most technical and non-technical people had never heard of came into the spotlight last week.  The vulnerability, called “Log4j,” “Log4Shell,” and “Logjam,” discovered, and subsequently patched, allows Remote Code Execution.  In non-technical terms, the Log4j vulnerability allows an attacker to execute unauthorized code on a computer with the flaw. 

Log4j is an open-source software library provided by the Apache Software Foundation.  Because the code is open source, the programmers responsible for the code are not being paid for creating the fix.  To make matters worse, the code is prolific; it is embedded into hundreds of thousands of applications—including many that are exposed directly to the Internet.

This vulnerability is being leveraged in the wild against hundreds of thousands of companies.  Basically, an attacker could leverage the flaw to install a remote access trojan to provide attackers with remote access to a vulnerable environment, even after the patches have been installed.  The attacker could also leverage the flaw to execute ransomware, and ultimately encrypt everything that the Log4j-vulnerable system has access to.

Threat attackers are actively using this vulnerability.  You should be patching your systems.  Due to complexity, limited programmers, and the open-source nature of the code, there have been and will be many patches for Log4j.  This vulnerability will be a problem for months and years to come.

There are some easy ways to mitigate and reduce your risks, such as implementing Crowdstrike with ThreatGraph, InsightEDR, Protect, OverWatch, and Spotlight.  But, you must patch your systems.

Here are some resources:

* * *

 

John Anthony Smith can be reached at:

423-305-7890

 

 

 

 

John.Smith@conversantgroup.com

1513 Cowart Street

Chattanooga, TN 37408


Breaking News
Latest Hamilton County Arrest Report
  • 7/9/2025

Here is the latest Hamilton County arrest report. (If your case is dismissed, just email us your name and date we ran it and we will promptly take off. Email to news@chattanoogan.com ) ALBAN,JONATHAN ... more

Dade County High School Student Struck And Killed By Train
  • 7/8/2025

A Dade County High School was struck and killed by a train in Trenton Monday morning. The incident happened at 11:30 a.m. near the Highway 136 East overpass. Principal Brent Cooper said, ... more

TDOT Holds Hearing On I-24 Widening, Including Around Congested Moccasin Bend
TDOT Holds Hearing On I-24 Widening, Including Around Congested Moccasin Bend
  • 7/8/2025

The Tennessee Department of Transportation hosted a public meeting on Tuesday to gather community input on a proposed project that would widen approximately 10 miles of I-24 from the I-24/I-59 ... more