Amazon's Hotpatch for Log4j Flaw Found Vulnerable to Privilege Escalation Bug

21-Apr-22

The vulnerability is identified as CVE-2022-0540 and has a severity rating of 9.9. By sending a carefully crafted HTTP request to susceptible endpoints, a remote attacker can bypass authentication.

Aside from containers, unprivileged processes can also exploit the patch to escalate privileges and acquire root code execution, according to a paper published this week by Palo Alto Networks Unit 42 researcher Yuval Avrahami. Read More…