← back
CVE-2024-49113highCWE-125

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 83%
exploitation probability
83%top 1% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Windows LDAP allows an attacker to crash the LDAP service by sending specially crafted requests, causing legitimate users to lose access to directory services. This affects systems that rely on LDAP for authentication and user management.

Technical detail

Out-of-bounds read vulnerability (CWE-125) in Windows LDAP protocol handler enables remote denial of service through malformed LDAP messages. The attack requires network access to an LDAP service and results in service termination, impacting availability of directory-dependent systems.

Summary generated and translated by AI from the official description.
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C