logo

Unpatched Active Directory Flaw Can Crash Any Microsoft Server

ID: a8dc8f14-5214-526c-b794-ec76b2eaf85d

STIX ID: report--a8dc8f14-5214-526c-b794-ec76b2eaf85d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-02

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Microsoft patched two critical Active Directory LDAP vulnerabilities (CVE-2024-49112 and CVE-2024-49113) that enable denial-of-service and potential remote code execution against domain controllers; SafeBreach analysis found the DoS bug can be escalated to crash multiple Windows servers if domain controllers expose DNS to the Internet. Proof-of-concept/exploit code has been published, administrators are urged to apply December patches or deploy compensating LDAP/RPC firewall controls, and there is currently no confirmed evidence of active exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.