Unpatched Active Directory Flaw Can Crash Any Microsoft Server

Share:

Windows servers are vulnerable to a dangerous LDAP vulnerability that could be used to crash multiple servers at once and should be patched immediately.

One of two critical Active Directory Domain Controller vulnerabilities patched by Microsoft last month goes beyond the original denial-of-service (DoS) attack chain and can be used to crash multiple, unpatched Windows servers at once. And experts are concerned many organizations remain vulnerable.

Researchers at SafeBreach have put together an analysis of the DoS bug, tracked as CVE-2024-49113. This vulnerability, along with a similar remote control execution (RCE) bug, tracked as CVE-2024-49112, with a CVSS score of 9.8, was discovered in Active Directory’s Lightweight Directory Access Protocol (LDAP) used to search the databases. Both were patched in December’s Microsoft security update.

Microsoft hasn’t provided many details about the LDAP flaws, despite their severity and potential impact, which is why SafeBreach said it decided to dig deeper and find out more.

“LDAP is the protocol that workstations and servers in Microsoft’s Active Directory use to access and maintain directory services information,” the SafeBreach report explained.

Additional analysis of the DoS LDAP bug showed the attack chain could also be used by a threat actor to achieve RCE but, worse yet, could be exploited to crash any Windows server, as long as the target system’s domain controller has a DNS server connected to the Internet.

Why The Microsoft LDAP Flaw Is So Dangerous

Prior to December’s Patch Tuesday update, every single organization running Windows Servers was vulnerable to the flaw, Tal Be’ery, chief technology officer and co-founder of Zengo Wallet, explains.

“So the question is, how many of these organizations patched all of their systems and mainly domain controllers?” he adds.

There’s no indication yet the vulnerability is being exploited in the wild, but Be’ery points to PatchPoint’s release of exploit code as a signal to threat actors.

“We assume that such code is already being used, but we don’t have any positive evidence for it yet,” he adds.

Threat actors typically have to work their way from a single, hacked device through what Be’ery compares to a Chutes and Ladders game-like maze, ultimately hopping their way from one compromise to the big prize — the domain controller stuffed full of credentials. It’s the time these hackers spend trying to work their way deeper into the system that affords defenders opportunities to stop the cyberattack before it escalates.

“With this LDAP vulnerability hackers can go immediately straight from square 1 to 100 [domain controllers] before defenders can respond,” he adds.

The SafeBreach research also confirmed Microsoft’s December 2024 patches are effective, so administrators are urged to patch Windows Servers and all domain controllers immediately.

If servers can’t be patched, Be’ery recommends defenders “use compensating controls such as LDAP and RPC firewalls to block the exploit of this vulnerability.”

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:34 am, Jun 10, 2025
weather icon 14°C
L: 14° | H: 15°
broken clouds
Humidity: 79 %
Pressure: 1016 mb
Wind: 15 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
14° | 15°°C 0.39 mm 39% 11 mph 83 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 24°°C 0 mm 0% 11 mph 91 % 1021 mb 0 mm/h
Thu Jun 12 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 11 mph 75 % 1017 mb 0 mm/h
Fri Jun 13 10:00 pm
weather icon
16° | 28°°C 1 mm 100% 12 mph 93 % 1020 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
18° | 27°°C 1 mm 100% 8 mph 96 % 1019 mb 0 mm/h
Today 4:00 am
weather icon
14° | 14°°C 0 mm 0% 11 mph 79 % 1016 mb 0 mm/h
Today 7:00 am
weather icon
15° | 15°°C 0 mm 0% 10 mph 81 % 1016 mb 0 mm/h
Today 10:00 am
weather icon
16° | 17°°C 0 mm 0% 11 mph 83 % 1016 mb 0 mm/h
Today 1:00 pm
weather icon
20° | 20°°C 0.39 mm 39% 11 mph 65 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
22° | 22°°C 0.2 mm 20% 10 mph 52 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
20° | 20°°C 0 mm 0% 6 mph 46 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 4 mph 65 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 14°°C 0 mm 0% 4 mph 77 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€96,193.01
3.95%
Ethereum(ETH)
€2,372.44
8.27%
Tether(USDT)
€0.88
-0.01%
XRP(XRP)
€2.02
2.66%
Solana(SOL)
€140.64
5.56%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.170914
6.55%
Shiba Inu(SHIB)
€0.000011
5.02%
Pepe(PEPE)
€0.000011
9.47%
Peanut the Squirrel(PNUT)
€0.256317
11.91%
Scroll to Top