ZeroHour

CVE-2024-49112

mass1

Unauthenticated RCE in Microsoft Windows LDAP (CVE-2024-49112)

CVSS 3.1
9.8 critical
EPSS
71%p99
Published
()
Modified
AI analysis

CVE-2024-49112 is an integer overflow (CWE-190) in the Windows Lightweight Directory Access Protocol (LDAP) implementation that permits remote code execution. It is triggered by network traffic sent to the LDAP service, with no authentication or user interaction required (CVSS 3.1 network vector, low complexity, no privileges). A successful attacker gains arbitrary code execution in the context of the LDAP service process on the target, and on Active Directory domain controllers this typically means compromising a core infrastructure host with high confidentiality, integrity, and availability impact. All listed Windows 10 and Windows 11 client versions and Windows Server 2008 through 2022 are affected, making virtually every unpatched Windows environment — especially those running domain controllers — exposed. Per related coverage, the flaw was addressed in Microsoft's December 2024 Patch Tuesday (72 flaws fixed, four rated critical); no public proof-of-concept or confirmed in-the-wild exploitation is known for this specific RCE yet, though a related Windows LDAP flaw ('LDAPNightmare') has a public PoC that crashes LSASS and reboots domain controllers, and the ~71% EPSS score signals a high likelihood of exploitation within 30 days.

What to do: Apply Microsoft's December 2024 (or later) Windows security updates immediately, prioritizing domain controllers and any server with LDAP reachable from untrusted networks. Until fully patched, restrict inbound LDAP/LDAPS traffic (TCP and UDP 389 and 636) to trusted sources and monitor for LSASS crashes or restarts on domain controllers. Because fixes are version-specific cumulative updates, verify each Windows release against Microsoft's advisory to confirm the correct KB is installed.

Affected
Microsoft Windows 101507, 1607, 1809, 21H2, 22H2 (builds prior to the December 2024 security updates)
Microsoft Windows 1122H2, 24H2 (builds prior to the December 2024 security updates)
Microsoft Windows Server 2008affected builds prior to the December 2024 security updates
Microsoft Windows Server 2012affected builds prior to the December 2024 security updates
Microsoft Windows Server 2016affected builds prior to the December 2024 security updates
Microsoft Windows Server 2019affected builds prior to the December 2024 security updates
Microsoft Windows Server 2022affected builds prior to the December 2024 security updates
Estimated exposure
massorder of millions of systems — LDAP code ships with every affected Windows install, with millions of Active Directory domain controllers and servers deployed… — Windows runs on over a billion devices and Active Directory domain controllers are deployed in the millions across organizations, and the vulnerable LDAP component is present on all of them, so the affected population is effectively the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news