Description

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

INFO

Published Date :

Dec. 12, 2024, 2:04 a.m.

Last Modified :

Dec. 12, 2024, 2:04 a.m.

Remotely Exploitable :

Yes !

Impact Score :

3.6

Exploitability Score :

3.9
Public PoC/Exploit Available at Github

CVE-2024-49113 has a 6 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2024-49113 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Microsoft windows_server_2012
2 Microsoft windows_server_2016
3 Microsoft windows_server_2019
4 Microsoft windows_server_2022
5 Microsoft windows_11_22h2
6 Microsoft windows_server_2022_23h2
7 Microsoft windows_11_24h2
8 Microsoft windows_server_2025
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2024-49113.

URL Resource
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Hi, This is to check targets vulnerable for CVE-2024-49113 in bulk, faster.

Python

Updated: 5 days, 12 hours ago
0 stars 0 fork 0 watcher
Born at : Jan. 6, 2025, 11:59 a.m. This repo has been linked 1 different CVEs too.

CVE-2024-49113에 대한 익스플로잇. Windows Lightweight Directory Access Protocol(LDAP)의 취약성.

Updated: 6 days, 23 hours ago
0 stars 0 fork 0 watcher
Born at : Jan. 5, 2025, 1:32 a.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 4 days, 9 hours ago
6 stars 0 fork 0 watcher
Born at : Jan. 3, 2025, 7:05 a.m. This repo has been linked 1 different CVEs too.

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

Python

Updated: 2 days, 2 hours ago
416 stars 99 fork 99 watcher
Born at : Jan. 1, 2025, 3:48 p.m. This repo has been linked 1 different CVEs too.

GitHub 热门项目

Python

Updated: 6 days, 23 hours ago
0 stars 0 fork 0 watcher
Born at : Dec. 1, 2024, 7:58 a.m. This repo has been linked 1 different CVEs too.

This repository aims to be a comprehensive collection of resources related to information security. Here, you will find a variety of scripts, programs, tutorials, and cheat sheets designed to assist security professionals, enthusiasts, and learners.

PowerShell Shell

Updated: 1 day, 13 hours ago
1 stars 0 fork 0 watcher
Born at : Nov. 11, 2024, 12:42 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-49113 vulnerability anywhere in the article.

  • BleepingComputer
Fake LDAPNightmware exploit on GitHub spreads infostealer malware

A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server. The tact ... Read more

Published Date: Jan 11, 2025 (9 hours, 29 minutes ago)
  • tripwire.com
Tripwire Patch Priority Index for December 2024

Tripwire's December 2024 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft and Adobe.First on the list is a notice about Windows Common Log File System Driver (CLFS). ... Read more

Published Date: Jan 10, 2025 (1 day, 15 hours ago)
  • The Hacker News
CrowdStrike Warns of Phishing Scam Targeting Job Seekers with XMRig Cryptominer

Cybersecurity company CrowdStrike is alerting of a phishing campaign that exploits its own branding to distribute a cryptocurrency miner that's disguised as an employee CRM application as part of a su ... Read more

Published Date: Jan 10, 2025 (1 day, 15 hours ago)
  • Help Net Security
January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance

Welcome to 2025 and a new year of patch excitement! In my December article, I talked about Microsoft’s Secure Future Initiative (SFI) and how it manifested in many of the Microsoft products released i ... Read more

Published Date: Jan 10, 2025 (1 day, 17 hours ago)
  • Cybersecurity News
Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware

Trend Micro researchers have uncovered a dangerous fake proof-of-concept (PoC) exploit masquerading as an exploit for CVE-2024-49113, a critical vulnerability in Microsoft’s Lightweight Directory Acce ... Read more

Published Date: Jan 10, 2025 (1 day, 22 hours ago)
  • The Register
Security pros baited with fake Windows LDAP exploit traps

Security researchers are once again being lured into traps by attackers, this time with fake exploits of serious Microsoft security flaws. Trend Micro spotted what appears to be a fork of the legitima ... Read more

Published Date: Jan 09, 2025 (2 days, 11 hours ago)
  • TheCyberThrone
CVE-2025-0282: Affecting Ivanti Products

OverviewCVE-2025-0282 is a critical stack-based buffer overflow vulnerability. It impacts Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for Zero Trust Access (ZTA) gateways. This vul ... Read more

Published Date: Jan 09, 2025 (2 days, 23 hours ago)
  • Trend Micro
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit

In December 2024, two critical vulnerabilities in Microsoft's Windows Lightweight Directory Access Protocol (LDAP) were addressed via Microsoft’s monthly Patch Tuesday release. Both vulnerabilities we ... Read more

Published Date: Jan 09, 2025 (3 days ago)
  • TheCyberThrone
Redis was affected by CVE-2024-51741 and CVE-2024-46981

CVE-2024-51741Description:This vulnerability affects Redis, an open-source in-memory data structure store used as a database, cache, and message broker. The issue arises when an authenticated user wit ... Read more

Published Date: Jan 07, 2025 (4 days, 11 hours ago)
  • The Hacker News
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan]

Every tap, click, and swipe we make online shapes our digital lives, but it also opens doors—some we never meant to unlock. Extensions we trust, assistants we rely on, and even the codes we scan are t ... Read more

Published Date: Jan 06, 2025 (5 days, 12 hours ago)
  • TheCyberThrone
CVE-2024-10957: UpdraftPlus WordPress Plugin Vulnerability

CVE-2024-10957 is a high-severity vulnerability affecting the UpdraftPlus: WP Backup & Migration Plugin for WordPress. This vulnerability, present in versions up to and including 1.24.11, enables atta ... Read more

Published Date: Jan 06, 2025 (5 days, 15 hours ago)
  • TheCyberThrone
CVE-2024-43405 Vulnerability in Nuclei

CVE-2024-43405 is a high severity vulnerability identified in Nuclei, a widely used open-source vulnerability scanner. This vulnerability, affecting versions 3.0.0 to 3.3.1, allows attackers to bypass ... Read more

Published Date: Jan 06, 2025 (5 days, 22 hours ago)
  • TheCyberThrone
TheCyberThrone Security Weekly Review – January 04, 2025

Welcome to TheCyberThrone cybersecurity week in review will be posted covering the important security happenings. This review is for the week ending Saturday, January 04, 2025.CVE-2024-56512 impacts A ... Read more

Published Date: Jan 05, 2025 (6 days, 12 hours ago)
  • TheCyberThrone
CVE-2024-11944: TrueNAS CORE has Severe Directory Traversal Flaw

CVE-2024-11944 is a vulnerability identified in iXsystems TrueNAS CORE. This vulnerability is classified as a Directory Traversal and Remote Code Execution (RCE) flaw. The exploitation of this vulnera ... Read more

Published Date: Jan 04, 2025 (1 week ago)
  • Trend Micro
What We Know About CVE-2024-49112 and CVE-2024-49113

In December 2024, two Windows Lightweight Directory Access Protocol (LDAP) vulnerabilities were identified by independent security researcher Yuki Chen: CVE-2024-49112, a remote code execution (RCE) f ... Read more

Published Date: Jan 04, 2025 (1 week, 1 day ago)
  • TheCyberThrone
CVE-2024-49113: PoC Exploit Code Released

The CVE-2024-49113 vulnerability is a significant Denial of Service (DoS) issue found in the Windows Lightweight Directory Access Protocol (LDAP). SafeBreach Labs developed the exploit code, which has ... Read more

Published Date: Jan 03, 2025 (1 week, 1 day ago)
  • The Hacker News
LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

Windows Server / Threat Mitigation A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger ... Read more

Published Date: Jan 03, 2025 (1 week, 1 day ago)
  • Dark Reading
Unpatched Active Directory Flaw Can Crash Any Microsoft Server

Source: Andriy Popov via Alamy Stock PhotoOne of two critical Active Directory Domain Controller vulnerabilities patched by Microsoft last month goes beyond the original denial-of-service (DoS) attack ... Read more

Published Date: Jan 02, 2025 (1 week, 2 days ago)
  • tripwire.com
VERT Threat Alert: December 2024 Patch Tuesday Analysis

Today’s VERT Alert addresses Microsoft’s December 2024 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1136 as soon as coverage is completed.I ... Read more

Published Date: Dec 10, 2024 (1 month ago)
  • BleepingComputer
Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws

Today is Microsoft's December 2024 Patch Tuesday, which includes security updates for 71 flaws, including one actively exploited zero-day vulnerability.This Patch Tuesday fixed sixteen critical vulner ... Read more

Published Date: Dec 10, 2024 (1 month ago)

The following table lists the changes that have been made to the CVE-2024-49113 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by [email protected]

    Dec. 12, 2024

    Action Type Old Value New Value
    Added Description Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-125
    Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-49113 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2024-49113 weaknesses.

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability