Unpatched Active Directory Flaw Can Crash Any Microsoft Server

Teilen:

Windows servers are vulnerable to a dangerous LDAP vulnerability that could be used to crash multiple servers at once and should be patched immediately.

One of two critical Active Directory Domain Controller vulnerabilities patched by Microsoft last month goes beyond the original denial-of-service (DoS) attack chain and can be used to crash multiple, unpatched Windows servers at once. And experts are concerned many organizations remain vulnerable.

Researchers at SafeBreach have put together an analysis of the DoS bug, tracked as CVE-2024-49113. This vulnerability, along with a similar remote control execution (RCE) bug, tracked as CVE-2024-49112, with a CVSS score of 9.8, was discovered in Active Directory’s Lightweight Directory Access Protocol (LDAP) used to search the databases. Both were patched in December’s Microsoft security update.

Microsoft hasn’t provided many details about the LDAP flaws, despite their severity and potential impact, which is why SafeBreach said it decided to dig deeper and find out more.

“LDAP is the protocol that workstations and servers in Microsoft’s Active Directory use to access and maintain directory services information,” the SafeBreach report explained.

Additional analysis of the DoS LDAP bug showed the attack chain could also be used by a threat actor to achieve RCE but, worse yet, could be exploited to crash any Windows server, as long as the target system’s domain controller has a DNS server connected to the Internet.

Why The Microsoft LDAP Flaw Is So Dangerous

Prior to December’s Patch Tuesday update, every single organization running Windows Servers was vulnerable to the flaw, Tal Be’ery, chief technology officer and co-founder of Zengo Wallet, explains.

“So the question is, how many of these organizations patched all of their systems and mainly domain controllers?” he adds.

There’s no indication yet the vulnerability is being exploited in the wild, but Be’ery points to PatchPoint’s release of exploit code as a signal to threat actors.

“We assume that such code is already being used, but we don’t have any positive evidence for it yet,” he adds.

Threat actors typically have to work their way from a single, hacked device through what Be’ery compares to a Chutes and Ladders game-like maze, ultimately hopping their way from one compromise to the big prize — the domain controller stuffed full of credentials. It’s the time these hackers spend trying to work their way deeper into the system that affords defenders opportunities to stop the cyberattack before it escalates.

“With this LDAP vulnerability hackers can go immediately straight from square 1 to 100 [domain controllers] before defenders can respond,” he adds.

The SafeBreach research also confirmed Microsoft’s December 2024 patches are effective, so administrators are urged to patch Windows Servers and all domain controllers immediately.

If servers can’t be patched, Be’ery recommends defenders “use compensating controls such as LDAP and RPC firewalls to block the exploit of this vulnerability.”

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:06 am, Juli 11, 2025
Wetter-Symbol 19°C
L: 17° | H: 19°
broken clouds
Luftfeuchtigkeit: 78 %
Druck: 1021 mb
Wind: 7 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 60%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 9:15 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 8 mph 78 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mo. Juli 14 10:00 pm
Wetter-Symbol
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
16° | 19°°C 0 mm 0% 3 mph 78 % 1021 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 2 mph 74 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
24° | 27°°C 0 mm 0% 2 mph 56 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 3 mph 32 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,071.86
4.18%
Ethereum(ETH)
€2,523.83
6.33%
Fesseln(USDT)
€0.85
-0.02%
XRP(XRP)
€2.18
4.85%
Solana(SOL)
€140.30
3.86%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.167233
8.10%
Shiba Inu(SHIB)
€0.000011
8.25%
Pepe(PEPE)
€0.000010
13.31%
Peanut das Eichhörnchen(PNUT)
€0.245548
22.13%
Nach oben scrollen