Unpatched Active Directory Flaw Can Crash Any Microsoft Server
ID: a8dc8f14-5214-526c-b794-ec76b2eaf85d
STIX ID: report--a8dc8f14-5214-526c-b794-ec76b2eaf85d
Feed Name: Dark Reading
Date Published: 2025-01-02
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Microsoft patched two critical Active Directory LDAP vulnerabilities (CVE-2024-49112 and CVE-2024-49113) that enable denial-of-service and potential remote code execution against domain controllers; SafeBreach analysis found the DoS bug can be escalated to crash multiple Windows servers if domain controllers expose DNS to the Internet. Proof-of-concept/exploit code has been published, administrators are urged to apply December patches or deploy compensating LDAP/RPC firewall controls, and there is currently no confirmed evidence of active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
