By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers
Tech News

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

By Viral Trending Content 3 Min Read
Share
SHARE

Jan 03, 2025Ravie LakshmananWindows Server / Threat Mitigation

LDAPNightmare PoC Exploit

A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger a denial-of-service (DoS) condition.

The out-of-bounds reads vulnerability is tracked as CVE-2024-49113 (CVSS score: 7.5). It was addressed by Microsoft as part of Patch Tuesday updates for December 2024, alongside CVE-2024-49112 (CVSS score: 9.8), a critical integer overflow flaw in the same component that could result in remote code execution.

Credited with discovering and reporting both vulnerabilities is independent security researcher Yuki Chen (@guhe120).

Cybersecurity

The CVE-2024-49113 PoC devised by SafeBreach Labs, codenamed LDAPNightmare, is designed to crash any unpatched Windows Server “with no pre-requisites except that the DNS server of the victim DC has Internet connectivity.”

Specifically, it entails sending a DCE/RPC request to the victim server, ultimately causing the Local Security Authority Subsystem Service (LSASS) to crash and force a reboot when a specially crafted CLDAP referral response packet.

Even worse, the California-based cybersecurity company found that the same exploit chain could also be leveraged to achieve remote code execution (CVE-2024-49112) by modifying the CLDAP packet.

Microsoft’s advisory for CVE-2024-49113 is lean on technical details, but the Windows maker has revealed that CVE-2024-49112 could be exploited by sending RPC requests from untrusted networks to execute arbitrary code within the context of the LDAP service.

“In the context of exploiting a domain controller for an LDAP server, to be successful an attacker must send specially crafted RPC calls to the target to trigger a lookup of the attacker’s domain to be performed in order to be successful,” Microsoft said.

“In the context of exploiting an LDAP client application, to be successful an attacker must convince or trick the victim into performing a domain controller lookup for the attacker’s domain or into connecting to a malicious LDAP server. However, unauthenticated RPC calls would not succeed.”

Cybersecurity

Furthermore, an attacker could use an RPC connection to a domain controller to trigger domain controller lookup operations against the attacker’s domain, the company noted.

To mitigate the risk posed by these vulnerabilities, it’s essential that organizations apply the December 2024 patches released by Microsoft. In situations where immediate patching is not possible, it’s advised to “implement detections to monitor suspicious CLDAP referral responses (with the specific malicious value set), suspicious DsrGetDcNameEx2 calls, and suspicious DNS SRV queries.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Google Pixel Phone eSIM Bug Widely Reported

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Apple iOS 27 Release: Everything New Coming to Your iPhone

Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw

In 2026, what medtech skills will empower you to face the future head on?

TAGGED: Cyber Security, Cybersecurity, Denial of Service, Internet, LDAP, Microsoft, Remote Code Execution, Threat Mitigation, Windows Server
Share This Article
Facebook Twitter Copy Link
Previous Article Base mulls launching tokenized COIN stock
Next Article Bank of Marin Bancorp to Webcast Q4 Earnings on Monday, January 27, 2025, at 8:30 a.m. PT
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Arcade Cabinets For A Satirical Trump RPG Have Appeared In Washington D.C.
Gaming News
14 new beaches in Italy have been awarded Blue Flags – here’s where they are
Travel
How Trump’s ‘unusual’ brokerage account traded around his own market-moving decisions—selling hyperscalers and buying energy stocks during the war
Business
Norway defends move to cancel missile system sale following criticism from Malaysia
World News
US CLARITY Act brings ‘major spike of euphoria’ to Bitcoin: Santiment
Crypto
Cardano (ADA) Could Launch New Bull Phase With Investor Confidence On The Rise
Crypto
Exodus Gameplay Snippet Teases The Guarding Maze and More
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Arcade Cabinets For A Satirical Trump RPG Have Appeared In Washington D.C.

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Arcade Cabinets For A Satirical Trump RPG Have Appeared In Washington D.C.
May 16, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?