Advertisement
Untold millions of servers have it installed, and experts said the fallout would not be known for several days.
New Zealand’s computer emergency response team was among the first to report that the flaw in a Java-language utility for Apache servers used to log user activity was being “actively exploited in the wild” just hours after it was publicly reported Thursday and a patch released.
The vulnerability, dubbed ‘Log4Shell,’ was rated 10 on a scale of one to 10, the worst possible. Anyone with the exploit can get full access to an unpatched machine.
Related Articles
Advertisement
The vulnerability in the Apache Software Foundation module was discovered November 24 by the Chinese tech giant Alibaba, the foundation said.
Meyers expected computer emergency response teams to have a busy weekend trying to identify all impacted machines. The hunt is complicated by the fact that affected software can be in programs provided by third parties. The flaw’s exploitation was apparently first discovered in Minecraft, an online game hugely popular with kids and owned by Microsoft.
Meyers and security expert Marcus Hutchins said Minecraft users had already been using it to execute programs on the computers of other users by pasting a short message in a chatbox.
Microsoft said it had issued a software update for Minecraft users and “customers who apply the fix are protected.” Researchers reported finding evidence the vulnerability could be exploited in servers run by companies including Apple, Amazon, Twitter, and Cloudflare.
Cloudflare’s Sullivan said there we no indication his company’s servers had been compromised. Apple, Amazon, and Twitter did not immediately respond to requests for comment.