A vulnerability identified in Windows LDAP has been assigned the identifier CVE-2024-49113, accompanied by a recently released proof-of-concept (PoC) exploit. With a CVSS score of 7.5, the flaw can lead to a denial-of-service (DoS) condition, causing the LSASS service to crash and necessitating a system restart. Security researcher Yuki Chen independently discovered the vulnerability, which was patched as part of Microsoft’s December 2024 Patch Tuesday updates. This update also addressed CVE-2024-49112, a critical remote code execution (RCE) vulnerability rated at 9.8 on the CVSS scale. SafeBreach Labs developed the LDAPNightmare PoC, which can crash any unpatched Windows Server without requiring significant preconditions beyond the victim's DNS server having internet connectivity. The exploit leverages a DCE/RPC request sent to the target system, which triggers a crash when processing a specially crafted CLDAP referral response packet. With minor modifications, the same exploit chain can be adapted to execute remote code by altering the CLDAP packet to target CVE-2024-49112. Microsoft’s advisory on CVE-2024-49113 does not provide in-depth technical details but highlights that CVE-2024-49112 can be exploited if the LDAP service accepts RPC requests. The attack is feasible against systems that either perform domain controller lookups for malicious domains or connect to rogue LDAP servers. However, unauthenticated RPC calls in LDAP client applications would fail, limiting some exploitation scenarios. Organizations are strongly encouraged to apply the December 2024 security updates to mitigate these vulnerabilities. For those unable to patch immediately, Microsoft recommends monitoring for suspicious activity, including CLDAP referral responses, DsrGetDcNameEx2 calls, and DNS SRV queries, to detect potential exploitation attempts.
A recently disclosed supply chain vulnerability in Anthropic’s Claude Code GitHub Actions integration exposed numerous repositories to potential compromise through a single malic...
A critical security vulnerability affecting KMW CCTV cameras has been disclosed under CVE-2026-5386. The flaw allows attackers to bypass authentication controls and change device c...
A critical vulnerability, tracked as CVE-2026-4387, has been disclosed in StrongDM, exposing organizations to authentication token theft and session hijacking. Discovered by Specte...