A reported Apache Log4j2 deserialization flaw, tracked as Issue #4255, may allow attackers to bypass FilteredObjectInputStream protections through the allowlisted java.rmi.MarshalledObject class. During native serialized LogEvent processing, Log4jLogEvent.LogEventProxy.readResolve() can invoke MarshalledObject.get(), deserializing an embedded object with an unfiltered ObjectInputStream; a compatible gadget chain on the target classpath could then enable remote code execution. The issue may also permit resource-exhaustion denial of service and log injection.
Exposure is limited to services that accept native Java-serialized Log4j event objects over the network, rather than ordinary local logging or non-native log transports. A Nuclei template has been proposed to detect blind out-of-band exploitation using Interactsh DNS callbacks against ObjectInputStreamLogEventBridge-style receivers. Reported affected releases include log4j-api and log4j-core through 2.26.1; an Apache patch and CVE assignment were pending. Rejecting java.rmi.MarshalledObject with -Djdk.serialFilter='!java.rmi.MarshalledObject' blocks the tested deserialization path.

See affected versions and whether adversaries are exploiting it.
8 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcethecybersecguru.com
Open sourcesecurityonline.info
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.