Log4j CVE-2021-44228

You may have seen this in InsightVM with the latest release (and I know it was mentioned just above ^^) but we have an update: :mega:

With product version 6.6.121, we have made updates to add an authenticated check for CVE-2021-44228 on Windows devices. This update provides the option to enable Windows File System Search to allow scan engines to search your local filesystems for specific files on Windows assets. Scan engines and consoles should be updated to version 6.6.121 for this, which will require a restart. Windows File System Search must be enabled in the scan template for this check, and WMI needs to be enabled in your environment.

Since Windows filesystem searches can be resource intensive, there’s the potential that these scans will take longer than usual. If you have any concerns about scan time or impact on your devices, you can always stop the scan and disable Windows File System Search.

I’ll continue sharing more info as we have it. Appreciate everyone’s patience as we’ve been working on getting this out!

1 Like