Loading...

Text4Shell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-42889

Text4Shell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-42889

Author: Eliran Azulai, Principal Program Manager, Azure Networking  

Co-author: Gunjan Jain, Principal PM Manager, Azure Networking 

 

Similar to the Spring4Shell and Log4Shell vulnerabilities, a new critical vulnerabilityCVE-2022-42889 aka Text4Shell was discovered on October 13, 2022.

 

Text4Shell is a vulnerability in the Java library Apache Commons Text. This vulnerability, in specific conditions, allows an attacker to execute arbitrary code on the victim's machine (Remote Code Execution or "RCE").  

 

Customers can detect and protect their resources against Text4Shell vulnerability using Azure native network security services, Azure Firewall Premium and Azure Web Application Firewall (WAF). You can utilize one of these services or both for multi-layered defense.

 

Customers using Azure Firewall Premium, and Azure WAF have enhanced protection for this RCE vulnerability from the get-go.  Customers can protect their assets by upgrading their Apache Commons Text version to the patched version 1.10. However, there are situations when upgrading software is not an option or may take a long period of time. In such case, they can use products like Azure Firewall Premium and Azure WAF for protection.

 

Azure Firewall Premium Configuration

 

Azure Firewall premium IDPS (Intrusion Detection and Prevention System) ruleset was updated within a few hours to include CVE-2022-42889 vulnerability.  Azure Firewall Premium IDPS provides prevention and detection against active network attacks such as this, in a timely manner. Azure Firewall Premium with TLS inspection and IDPS capabilities protects customers against this vulnerability, you should have both TLSi and IDPS capabilities enabled.

 

IDPS should be configured either as ‘Alert’ or ‘Alert and Deny’ mode. IDPS signatures assigned with Text4Shell should be visible in Azure Portal in your Azure Firewall Policy as seen below:

 

gusmodena_0-1667155549208.png

 

Azure Web Application Firewall (WAF) Configuration

 

Azure WAF includes Microsoft managed rules out of box that provide protection against CVE-2022-42889 vulnerability. These rules are available with all versions of Default Rule Set (DRS) with Azure Front Door global deployments, and with all versions of Core Rule Set (CRS) with Azure Application Gateway regional deployments. There are multiple rules across Java, RCE, and XSS rule groups that help mitigate attack patterns for this CVE. In our internal testing, we found rules 932130 and 941210 to be quite effective in providing protection against this vulnerability. These protection rules are enabled by default to block exploit attempts to this vulnerability.  

 

More information about Default Rule Set (DRS) on Azure WAF with Azure Front Door can be found here. More information about Core Rule Set (CRS) on Azure WAF with Application Gateway can be found here.

 

Conclusion

 

At Microsoft, we are continuously monitoring for new & emerging threats to protect customer workloads running in Azure. Our signature pipelines are quickly updated within a few hours of detecting a threat. Customers are recommended to deploy Azure Firewall Premium for outbound network traffic and WAF for inbound HTTP/HTTPs traffic.

 

We will continue to monitor threat patterns and modify the rules and signatures in response to emerging attack patterns as required.

 

Learn More

 

Azure Firewall Premium and Azure WAF provide advanced threat protection capabilities to help detect and protect against Text4Shell and other exploits. For more information on everything we covered above, please see the following documentation:

 

Published on:

Learn more
Need help with this product?

We can help you with Text4Shell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-42889

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

Azure Network Security Blog articles
Azure Network Security Blog articles

Azure Network Security Blog articles

Share post:

Related posts

IPv6 Adoption: Enhancing Azure WAF on Front Door

The transition to IPv6 is a significant step for enterprise corporations, reflecting the evolution of internet technology and the need for a l...

1 year ago

Azure WAF’s Bot Manager 1.1 and JavaScript Challenge (Preview): Navigating the Bot Threat Terrain

Introduction   Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...

1 year ago

Private IP DNAT Support (Preview) and Scenarios with Azure Firewall

Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...

1 year ago

Getting Started with Azure DDoS Protection REST API: A Step-by-Step Guide

REST API is a cornerstone in the management of resources on Azure, providing a streamlined and efficient approach for executing create, read, ...

1 year ago

Monitoring Azure DDoS Protection Mitigation Triggers

Monitoring Azure DDoS Protection Mitigation Triggers In today’s digital landscape, Distributed Denial of Service (DDoS) attacks pose a signifi...

1 year ago

Azure WAF’s Bot Manager 1.1 and JavaScript Challenge: Navigating the Bot Threat Terrain

Introduction   Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...

1 year ago

Utilizing Azure DDoS Protection Workbook for DDoS attack traffic Analysis

In today's digital age, the security of applications, servers, and networks is paramount. One of the most significant threats to this security...

1 year ago

Independent Configuration of Size Enforcement and Inspection Limits in Application Gateway WAF

Introduction   In the constantly changing world of cybersecurity, both flexibility and effective security are essential for safeguarding ...

1 year ago

Private IP DNAT Support and Scenarios with Azure Firewall

Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...

1 year ago

Monitoring traffic flows in Azure Firewall using Virtual Network Flow Logs

Azure Firewall is a managed service designed to protect your Azure Virtual Network resources, providing advanced threat protection and advance...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.