← Vulnerability feed

Vulnerability record · CVE-2017-5645 · published 17 April 2017

CVE-2017-5645: Apache Log4j 2 socket server deserialization allows remote code execution

Apache · Log4j

Apache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted serialized object sent to that listener can trigger arbitrary code execution. Because the socket server is a network-facing component, any reachable deployment using it is exposed.

9.8 CVSS 3.1 Critical EPSS 90% · top 0.2% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
79Affected product versions listed by NVD
164References
17 Jun 2026Last modified by NVD

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, and a very high EPSS score, make this a high-impact remote code execution flaw.

What it is

Apache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted serialized object sent to that listener can trigger arbitrary code execution. Because the socket server is a network-facing component, any reachable deployment using it is exposed.

Impact

An unauthenticated remote attacker can execute arbitrary code with the privileges of the Log4j process, leading to full host compromise. This can result in data theft, lateral movement, or service disruption.

Attack surface

Reached over the network via the Log4j TCP or UDP socket server listener; the CVSS vector shows no privileges or user interaction required. Exploitation requires the socket server to be enabled and reachable by the attacker.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.89792, 99.78th percentile), indicating substantial predicted exploitation activity. References are patch advisories and third-party advisories, with no public exploit tag supplied.

What to do

  • Upgrade Apache Log4j 2.x to 2.8.2 or later, and apply vendor patches for affected Oracle, Red Hat, and NetApp products.
  • Disable the Log4j TCP and UDP socket server listeners where they are not strictly required.
  • Restrict network access to any Log4j socket server port to trusted hosts only, using firewall or segmentation controls.
  • If the socket server must remain enabled, use a Java deserialization filter or allowlist to block untrusted classes.
  • Inventory applications and embedded dependencies for bundled Log4j 2.x versions and track remediation.

Detection

  • Monitor network traffic to Log4j socket server ports for unexpected or anomalous serialized payloads.
  • Alert on Log4j process spawning child processes or making outbound connections it does not normally make.
  • Search logs for deserialization errors or exceptions from the Log4j socket server component.
  • Use file integrity monitoring and endpoint detection to catch post-exploitation activity on hosts running Log4j 2.x.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

79 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2019/12/19/2 Mailing ListThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Patch
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/97702 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040200 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1041294 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:1417 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1801 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1802 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2423 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2633 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2635 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2636 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2637 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2638 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2808 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2809 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2810 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2811 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2888 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2889 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3244 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3399 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3400 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1545 Third Party Advisory
https://issues.apache.org/jira/browse/LOG4J2-1863 Issue TrackingVendor Advisory
https://lists.apache.org/thread.html/0dcca05274d20ef2d72584edcf8c917bbb13dbbd7eb35cae909d02e9%40%3Cdev.logging.apache.or
https://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1%40%3Cdev.tika.apache.org%3
https://lists.apache.org/thread.html/44491fb9cc19acc901f7cff34acb7376619f15638439416e3e14761c%40%3Cdev.tika.apache.org%3
https://lists.apache.org/thread.html/479471e6debd608c837b9815b76eab24676657d4444fcfd5ef96d6e6%40%3Cdev.tika.apache.org%3
https://lists.apache.org/thread.html/6114ce566200d76e3cc45c521a62c2c5a4eac15738248f58a99f622c%40%3Cissues.activemq.apach
https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917%40%3Cannounce.apache.org%3
https://lists.apache.org/thread.html/8ab32b4c9f1826f20add7c40be08909de9f58a89dc1de9c09953f5ac%40%3Cissues.activemq.apach
https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.
https://lists.apache.org/thread.html/e8fb7d76a244ee997ba4b217d6171227f7c2521af8c7c5b16cba27bc%40%3Cdev.logging.apache.or
https://lists.apache.org/thread.html/eea03d504b36e8f870e8321d908e1def1addda16adda04327fe7c125%40%3Cdev.logging.apache.or
https://lists.apache.org/thread.html/r0831e2e52a390758ce39a6193f82c11c295175adce6e6307de28c287%40%3Cissues.beam.apache.o
https://lists.apache.org/thread.html/r18f1c010b554a3a2d761e8ffffd8674fd4747bcbcf16c643d708318c%40%3Cissues.activemq.apac

Track CVE-2017-5645 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed8.8CVE-2023-41993Apple WebKit improper check allows arbitrary code executionCVE-2023-41993 is a WebKit flaw where processing web content can lead to arbitrary code execution, addressed with improved checks. Apple states it is…KEVEPSS 24%analysed8.8CVE-2010-1871JBoss Seam 2 EL injection allows remote code executionJBoss Seam 2, as shipped in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, fails to sanitize input used in JBoss Expression Language …KEVEPSS 83%analysed8.1CVE-2018-11776Apache Struts namespace handling flaw enables remote code executionApache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are…KEVEPSS 100%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2017-5645), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.