Target Industry 

Indiscriminate, opportunistic targeting. 

Overview 

A significant vulnerability, CVE-2024-49113, has been identified in Windows Lightweight Directory Access Protocol (LDAP), which can lead to a Denial-of-Service (DoS) condition. This network-based vulnerability is particularly concerning due to its low attack complexity, as it requires neither user interaction nor elevated privileges to exploit. Classified as an Out-of-bounds Read (CWE-125), the flaw impacts Windows systems and has been assigned a CVSS base score of 7.5, indicating high severity.

Impact 

This vulnerability presents a significant threat by allowing an unauthenticated attacker to trigger a denial-of-service (DoS) condition in Windows LDAP services. The attack can be executed remotely over the network, which has the potential to disrupt the availability of critical directory services. Such disruption can lead to substantial operational impacts, particularly in environments that heavily rely on LDAP for authentication and authorisation processes. While the primary concern with this vulnerability is the impact on service availability, it does not compromise confidentiality or integrity.

Vulnerability Detection 

Multiple Windows versions are affected by the vulnerability. Refer to the following MRSC page to learn about the list of affected versions:

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113

Exploitation 

This vulnerability is being actively exploited in the wild.

Containment, Mitigations & Remediations 

A patch is available. Microsoft released an official fix for this vulnerability on 10th December 2024. It is crucial to apply this patch as soon as possible to mitigate the risk. The patch can be obtained through the Microsoft Update Guide at https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49113.

Indicators of Compromise

No indicators of compromise (IoCs) are available currently.

Threat Landscape 

Windows is used on many devices all over the world as it is one of the main operating systems organisations use. Many devices have not run the latest security update and this leaves them open to exploitation by threat actors.

Further Information 

1. https://www.scworld.com/brief/windows-ldap-vulnerability-gains-poc-exploit

2. https://securityaffairs.com/172618/security/ldapnightmare-exploit-cve-2024-49113.html

3. https://github.com/SafeBreach-Labs/CVE-2024-49113

4. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content