Log4Shell exploitation and hunting on VMware Horizon (CVE-2021-44228)
TLDR
Go and run this on the connection servers:
https://github.com/mr-r3b00t/CVE-2021-44228
It’s crude so also look for the modified timestamps, recent unexpected blast service restarts and if you have process logging go and check for suspicious child processes over the period. Once you have checked, run a backup, then if they aren’t patched, patch the servers! (i know patching isn’t as simple as just patch!)
Read more “Log4Shell exploitation and hunting on VMware Horizon (CVE-2021-44228)”