CVE-2021-45046

CVSS 9.0 · CRITICAL
Used in ransomware
Known ransomware association per CISA
Exploited in the wild
Remediation overdue by 1169 days
EPSS p100
Higher than 100% of all CVEs — imminent exploitation likely.
Patch available
Vendor advisory or patch linked

Published 12/14/2021 · updated 10/27/2025 · CWE-917

Share
Get asset-aware triage

Summary

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

CVSS 9.0CRITICAL

9.0 / 10
  • AV: Network
  • AC: High complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope changed
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS exploitation probability

94.3%

Percentile p100 Higher than 100% of all CVEs — imminent exploitation likely.

Affected products

55 vendor/product entries
  • Apache Log4j≥ 2.0.1 and < 2.12.2
  • Cvat Computer Vision Annotation Toolall versions
  • Intel Audio Development Kitall versions
  • Intel Datacenter Managerall versions
  • Intel Genomics Kernel Libraryall versions
  • Intel Oneapiall versions
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Dec 14, 2021 · Disclosed / published in NVD
  2. May 1, 2023 · Added to CISA KEV catalog
  3. May 22, 2023 · CISA remediation deadline
  4. Oct 27, 2025 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 60 days ago
  • CVE.org· no data
  • FIRST EPSS· 60 days ago
  • CISA KEV· 46 days ago
  • OSV· no data

Listed in CISA KEV

Added 2023-05-01 · Remediation overdue by 1169 days · used in known ransomware campaigns.

References

Patches & mitigations4
Vendor & CERT advisories18
Other3

Unlock the full report

See how CVE-2021-45046 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.