logo

Exploit released for new Windows Server "WinReg" NTLM Relay attack

ID: 52b59a17-432c-5856-8979-d441c443a2b8

STIX ID: report--52b59a17-432c-5856-8979-d441c443a2b8

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-10-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

*A proof-of-concept for CVE-2024-43532 (WinReg NTLM relay) was published after disclosure to Microsoft; the flaw allows an attacker to exploit a fallback RPC authentication path in the Remote Registry client to relay NTLM authentication to ADCS and obtain certificates that can enable domain takeover. The vulnerability affects Windows Server 2008–2022 and Windows 10/11, Microsoft has since confirmed and released a patch, and Akamai published detection guidance and a PoC.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.