← back
CVE-2024-49113

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVSS 7.5 HIGHEPSS 83.6%CWE-125
In short

A flaw in Windows LDAP allows an attacker to crash the LDAP service by sending specially crafted requests, causing legitimate users to lose access to directory services. This affects systems that rely on LDAP for authentication and user management.

Technical detail

Out-of-bounds read vulnerability (CWE-125) in Windows LDAP protocol handler enables remote denial of service through malformed LDAP messages. The attack requires network access to an LDAP service and results in service termination, impacting availability of directory-dependent systems.

Summary generated and translated by AI from the official description.
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →