web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Automate
Answered

log4j vulnerability

(1) ShareShare
ReportReport
Posted on by 25

In \Program Files (x86)\Power Automate Desktop\java-support\PAD.JavaBridge.jar, log4j 2.12.1 is used which is vulnerable with https://www.cvedetails.com/cve/CVE-2021-44228/ . @microsoft any plan for updating it?

I have the same question (0)
  • NikosMoutzou Profile Picture
    Microsoft Employee on at
    Regarding the CVE-2021-44228 log4j vulnerability (CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints-Apache Mail Archives), Power Automate for desktop does not use the log4j component since it is built on the .NET Framework, and not Java. The vulnerability has to do with services using this specific component for logging. While Power Automate for desktop is using it only for Java automation (automation of Java apps), and since it is not a service, it is not impacted. In any case, the latest version of Power Automate for desktop (to be released today Dec 14th) uses the latest log4j version that fixes this issue.
  • hbd Profile Picture
    25 on at

    I rather disagree. Since this file In \Program Files (x86)\Power Automate Desktop\java-support\PAD.JavaBridge.jar uses log4j 2.12.1 and it's owned by Microsoft, whoever using this service is vulnerable hence need to be updated by MS as the end-user doesn't own the code.

  • NikosMoutzou Profile Picture
    Microsoft Employee on at

    Hello @hbd .

     

    Please note that in the case of Power Automate for desktop, an attacker should initially get access to the specific machine, gain the necessary rights in order to be able to install a java application in this machine and then he/she would be able to take advantage of this vulnerability.

     

    Also, today, 12/15/2021, Microsoft has released a QFE version of Power Automate for desktop which uses the newest version of log4j, with the vulnerability resolved. The newest Power Automate for desktop version can be downloaded from all the default links.

  • hbd Profile Picture
    25 on at

    Yes, I have found that in the jar file with today's release, however 2.15 is still prone and Apache release 2.16 now. https://www.theregister.com/2021/12/14/apache_log4j_2_16_jndi_disabled/

    <groupId>org.apache.logging.log4j</groupId>
    <artifactId>log4j</artifactId>
    <version>2.15.0</version>
    <relativePath>../</relativePath>

  • Norro Profile Picture
    33 on at

    Can you specify which version number has been fixed? I can't see any patch notes mentioning this vulnerability to be sure we have a safe version.

    If a customer has already setup automation of a java app which has been attacked this vulnerable class can trigger code just by parsing the logs even if the app itself is secure.

  • hbd Profile Picture
    25 on at

    https://nvd.nist.gov/vuln/detail/CVE-2021-45046 This talks about log4j 2.15 is incomplete and 2.16 is required. PAD yesterday's release was using 2.15. 

  • hbd Profile Picture
    25 on at

    The latest release of PAD has fixed the log4j issue.

    hbd_0-1639669779639.png

     

    PAD version

    hbd_1-1639669800591.png

     

     

  • hbd Profile Picture
    25 on at

    Now log4j 2.17 is fixing DoS. 

    https://thehackernews.com/2021/12/new-local-attack-vector-expands-attack.html

     

    • CVE-2021-44228 (CVSS score: 10.0) - A remote code execution vulnerability affecting Log4j versions from 2.0-beta9 to 2.14.1 (Fixed in version 2.15.0)
    • CVE-2021-45046 (CVSS score: 9.0) - An information leak and remote code execution vulnerability affecting Log4j versions from 2.0-beta9 to 2.15.0, excluding 2.12.2 (Fixed in version 2.16.0)
    • CVE-2021-45105 (CVSS score: 7.5) - A denial-of-service vulnerability affecting Log4j versions from 2.0-beta9 to 2.16.0 (Fixed in version 2.17.0)
    • CVE-2021-4104 (CVSS score: 8.1) - An untrusted deserialization flaw affecting Log4j version 1.2 (No fix available; Upgrade to version 2.17.0)
  • kostasc Profile Picture
    Microsoft Employee on at

    Hey @hbd 

    We are currently working on addressing this issue and a fix should be available soon.

  • PatBerger Profile Picture
    3 on at

    HI kostasc,

     

    Any update on this? We have a few customers that use PDA and we'd like to be able to tell them that it has been patched.

     

    Regards,

    Pat

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the June Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Automate

#1
11manish Profile Picture

11manish 223

#2
David_MA Profile Picture

David_MA 195 Super User 2026 Season 1

#3
Haque Profile Picture

Haque 167

Last 30 days Overall leaderboard