NVIDIA has released a security advisory detailing which products are affected by the Log4Shell vulnerability (CVE-2021-4428), the recently discovered critical vulnerability in the Apache Log4j Java-based logging platform (and two other vulnerabilities in the same platform - CVE-2021-45046 and CVE-2021-45105). The vulnerability is already being exploited by many cybercriminals to carry out a variety of malware attacks .

After thorough investigation, NVIDIA has concluded that the Log4j vulnerability does not affect the following products:
- GeForce Experience client software
- GeForce NOW client software
- GPU Display Drivers for Windows
- L4T Jetson Products
- SHIELD TV
See also: Log4j Log4Shell vulnerability used to install Dridex banking trojan
NVIDIA: Impact of Log4j Log4Shell Vulnerability
While NVIDIA consumer applications are not affected, some enterprise applications include Apache Log4j and need to be updated:
- Nsight Eclipse Edition: versions below 11.0 are vulnerable to CVE-2021-33228 and CVE-2021-45046 and have been fixed in version 11.0 or later.
- NetQ: is vulnerable to CVE-2021-33228, CVE-2021-45046 and CVE-2021-45105 in versions 2.x, 3.x and 4.0.x. Therefore, users are advised to upgrade to NetQ 4.1.0 or later.
- vGPU Software License Server: affected by CVE-2021-33228 and CVE-2021-45046 in versions 2021.07 and 2020.05 Update 1. In these cases, it is advisable to follow this guide.
See also: TellYouThePass ransomware exploits Log4Shell vulnerability
NVIDIA also warns that the CUDA Toolkit Visual Profiler includes Log4j files but the application does not use them. An update will be released in January 2022 to remove these files.
Finally, by default, DGX Systems does not come with the Log4j library, but NVIDIA warns that some users may have installed it themselves. In these cases, users are advised to update to the latest available version of the library or remove it completely.

NVIDIA continues to conduct research to discover other products or services that may be affected by the critical vulnerability in Log4j.
On the other hand, AMD confirmed that none of its products are affected by the Log4shell exploit.
See also: Apache releases new 2.17.0 patch for Log4j
Unfortunately, many other products are affected, so all organizations should check their software and update it.
Even vulnerable internal applications need to be updated, as criminals are using the Log4Shell vulnerability to spread within networks to deploy ransomware.
Source: Bleeping Computer
