Hello @hbd .
Please note that in the case of Power Automate for desktop, an attacker should initially get access to the specific machine, gain the necessary rights in order to be able to install a java application in this machine and then he/she would be able to take advantage of this vulnerability.
Also, today, 12/15/2021, Microsoft has released a QFE version of Power Automate for desktop which uses the newest version of log4j, with the vulnerability resolved. The newest Power Automate for desktop version can be downloaded from all the default links.