logo

PoC Exploit Tool Released for Critical Windows LDAP Zero-click RCE Vulnerability

ID: 5b03cd44-f45a-5a5b-8cfd-0fd73ed6d793

STIX ID: report--5b03cd44-f45a-5a5b-8cfd-0fd73ed6d793

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-01-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Researchers disclosed CVE-2024-49112, a critical (CVSS 9.8) integer-overflow vulnerability in Windows LDAP that can lead to remote code execution and crashes of LSASS on Domain Controllers; SafeBreach Labs released a zero-click PoC dubbed “LDAPNightmare” demonstrating an attack flow that turns vulnerable servers into LDAP clients and triggers malicious referral responses. Microsoft published patches in December 2024 and organizations are urged to apply updates, monitor for suspicious DNS SRV/CLDAP activity and DsrGetDcNameEx2 calls, and test defenses with the provided PoC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.