Vulnerability record · CVE-2019-17571 · published 20 December 2019
CVE-2019-17571: Apache Log4j 1.2 SocketServer Deserialization RCE
Apache · Log4j
Log4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the classpath, an attacker can achieve remote code execution. The flaw affects Log4j versions up to and including 1.2.17.
Description
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS score is 9.8 (critical) and EPSS probability is high, indicating a severe, remotely exploitable flaw with significant potential impact.
What it is
Log4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the classpath, an attacker can achieve remote code execution. The flaw affects Log4j versions up to and including 1.2.17.
Impact
An attacker can execute arbitrary code on the host running the vulnerable SocketServer, leading to full system compromise. This can result in data theft, service disruption, or use of the host as a pivot point.
Attack surface
The vulnerability is reachable over the network via the SocketServer component listening for log data. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.6906, 99.3rd percentile). No public exploit references are tagged in the provided data.
What to do
- Upgrade to a supported version of Log4j that does not include the vulnerable SocketServer, or remove the SocketServer class if not needed.
- If SocketServer must be used, restrict network access to trusted sources and enable authentication where possible.
- Apply vendor patches for affected products (e.g., Debian, Ubuntu, openSUSE, NetApp, Oracle) as they become available.
- Monitor for deserialization attacks and consider using a deserialization filter or safe serialization library.
Detection
- Monitor network traffic to Log4j SocketServer ports for unexpected or malicious serialized objects.
- Inspect application logs for deserialization errors or unexpected class loading related to SocketServer.
- Use endpoint detection to identify processes spawning from Java applications running Log4j 1.2 with SocketServer enabled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-17571 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17571), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.