micrsoft azure active directory and apache log4j issue

fxconsulting 1 Reputation point
2021-12-17T02:53:52.183+00:00

The micro soft Active Directory server actually used by the customer and this time, a big issue broke out.

I wonder if it has anything to do with the apache log4j vulnerability issue

If so, how should the update be applied and what else?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,658 questions
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,311 Reputation points Microsoft Employee
    2021-12-20T07:02:05.157+00:00

    @fxconsulting Thanks for reaching out. Can you explain a bit what kind of issues are you talking about.
    Log4j 2 Remote Code Execution vulnerability affecting various industry-wide Apache products.

    Microsoft is aware of active exploitation of a critical Log4j 2 Remote Code Execution vulnerability affecting various industry-wide Apache products. This vulnerability is in the open source Java component Log4J 2 as documented in Apache CVE-2021-44228.

    We are taking steps to keep customers safe and protected - including performing a cross-company assessment to identify and remediate any impacted Microsoft services.

    Microsoft is not aware of any impact to the security of our enterprise services and has not experienced any degradation in the reliability or availability of those services as a result of this vulnerability. However, we are still actively investigating utilization of Log4j 2 in our services, and this determination may be subject to change at any given time based upon investigative findings. We will update this statement as the event warrants.

    We are also investigating for potential customer/partner impact. The Security update guide lists out services that require specific actions to customers to mitigate the risks posed by this vulnerability. If we identify additional services which require customers to take action, we will notify them through normal notification channels and continue to add these services to the Security update guide. Please subscribe to the security update guide to be notified when new services are added to this page. If a Microsoft service is not listed on this page, there is no action required by the customer at this time.

    We recommend that customers review Apache CVE-2021-44228 and the Apache security advisory (Apache Log4j 2 Security Vulnerabilities) for details about the vulnerability and references to additional resources that can be used to remediate the issue in customer environments.

    Guidance from Microsoft
    Please review the following guidance from Microsoft pertaining to this issue:
    MSRC Blog: Microsoft’s Response to CVE-2021-44228 Apache Log4j 2
    Microsoft Security blog: Guidance for preventing detecting and hunting for CVE-2021-44228 log4j2 exploitation
    Security Update Guide: CVE-2021-44228 | Microsoft - Apache Log4j Remote Code Execution Vulnerability

    Regarding the Minecraft Java Edition:
    Minecraft customers who apply the fix are protected.
    Please see Minecraft Wiki for further details:
    Minecraft Wiki: Java Edition 1.18.1 – Minecraft Wiki (fandom.com)

    Regarding M365 services:
    Q: Are M365 Services affected by Log4J 2 CVE-2021-44228?
    A: We have evaluated the Microsoft 365 service infrastructure and can confirm that we have not identified any impact to Microsoft 365 services or features at this time. We will continue to monitor for updates related to the Apache Log4j vulnerability and will take action as necessary. If there is a change to this impact assessment you will be notified directly via Message center.

    Regarding the Dynamics 365 services:
    Q: What can you tell me about the Dynamics 365 service infrastructure?
    A: We are investigating the Dynamics 365 service infrastructure to determine any impact related to the Log4j 2 vulnerability. If we identify any impact, you will notified directly via Message Center.

    We encourage our customers to practice industry-standard best practices for security and data protection including embracing the Zero Trust Security model and adopting robust strategies to manage product security updates, endpoint security updates, and passwords. More information on Zero Trust Security is available at https://aka.ms/zerotrust. Additional information is available at https://www.microsoft.com/en-us/security.

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.