Target Industry
Indiscriminate, opportunistic targeting.
Overview
A significant vulnerability, CVE-2024-49113, has been identified in Windows Lightweight Directory Access Protocol (LDAP), which can lead to a Denial-of-Service (DoS) condition. This network-based vulnerability is particularly concerning due to its low attack complexity, as it requires neither user interaction nor elevated privileges to exploit. Classified as an Out-of-bounds Read (CWE-125), the flaw impacts Windows systems and has been assigned a CVSS base score of 7.5, indicating high severity.
Impact
This vulnerability presents a significant threat by allowing an unauthenticated attacker to trigger a denial-of-service (DoS) condition in Windows LDAP services. The attack can be executed remotely over the network, which has the potential to disrupt the availability of critical directory services. Such disruption can lead to substantial operational impacts, particularly in environments that heavily rely on LDAP for authentication and authorisation processes. While the primary concern with this vulnerability is the impact on service availability, it does not compromise confidentiality or integrity.
Vulnerability Detection
Multiple Windows versions are affected by the vulnerability. Refer to the following MRSC page to learn about the list of affected versions:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113
Exploitation
This vulnerability is being actively exploited in the wild.
Containment, Mitigations & Remediations
A patch is available. Microsoft released an official fix for this vulnerability on 10th December 2024. It is crucial to apply this patch as soon as possible to mitigate the risk. The patch can be obtained through the Microsoft Update Guide at https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49113.
Indicators of Compromise
No indicators of compromise (IoCs) are available currently.
Threat Landscape
Windows is used on many devices all over the world as it is one of the main operating systems organisations use. Many devices have not run the latest security update and this leaves them open to exploitation by threat actors.
Further Information
1. https://www.scworld.com/brief/windows-ldap-vulnerability-gains-poc-exploit
2. https://securityaffairs.com/172618/security/ldapnightmare-exploit-cve-2024-49113.html
3. https://github.com/SafeBreach-Labs/CVE-2024-49113
4. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113












