PoC Exploit Tool Released for Critical Windows LDAP Zero-click RCE Vulnerability
ID: 5b03cd44-f45a-5a5b-8cfd-0fd73ed6d793
STIX ID: report--5b03cd44-f45a-5a5b-8cfd-0fd73ed6d793
Feed Name: cybersecurityNews.com
Researchers disclosed CVE-2024-49112, a critical (CVSS 9.8) integer-overflow vulnerability in Windows LDAP that can lead to remote code execution and crashes of LSASS on Domain Controllers; SafeBreach Labs released a zero-click PoC dubbed “LDAPNightmare” demonstrating an attack flow that turns vulnerable servers into LDAP clients and triggers malicious referral responses. Microsoft published patches in December 2024 and organizations are urged to apply updates, monitor for suspicious DNS SRV/CLDAP activity and DsrGetDcNameEx2 calls, and test defenses with the provided PoC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
