ZeroHour

CVE-2024-49113

mass1

Unauthenticated LDAP Denial-of-Service in Microsoft Windows

CVSS 3.1
7.5 high
EPSS
83%p100
Published
()
Modified
AI analysis

CVE-2024-49113 is an unauthenticated denial-of-service vulnerability in the Windows Lightweight Directory Access Protocol (LDAP) implementation, caused by an out-of-bounds read (CWE-125) and rated 7.5 (high) with network reachability, no privileges and no user interaction required. An attacker who can send crafted LDAP traffic to an affected Windows system can trigger the flaw, crashing the LSASS process; on domain controllers this crashes LSASS and reboots the server, taking authentication and directory services offline. Follow-up research ("Win-DDoS") also showed that internet-exposed domain controllers can be abused as DDoS amplification/reflection agents, extending the impact beyond a single-host outage. Affected systems span essentially all supported Windows clients and servers, from Windows 10 1507 and Windows Server 2008 through Windows 11 24H2 and Windows Server 2022. A public proof-of-concept exploit ("LDAPNightmare") demonstrating an LSASS crash and domain controller reboot has been widely reported; the flaw is not yet in CISA's KEV, but EPSS places it in the 100th percentile with an 83% probability of exploitation within 30 days.

What to do: Apply the January 2025 Microsoft security updates for CVE-2024-49113, prioritizing domain controllers and other internet-reachable Windows servers. Reduce exposure by not publishing LDAP (389/636) directly to the internet, restricting outbound LDAP referral traffic/egress from domain controllers, and monitoring for LSASS crashes and unexpected reboots. When validating with PoC tooling, use only trusted sources, as fake PoC repositories distributing infostealers and RATs have been reported targeting researchers.

Affected
Microsoft Windows 101507, 1607, 1809, 21H2, 22H2
Microsoft Windows 1122H2, 24H2
Microsoft Windows Server2008, 2012, 2016, 2019, 2022
Estimated exposure
massmass — millions of affected Windows installations, including hundreds of thousands of domain controllers and other LDAP-exposed Windows servers — Every supported Windows client and server release is listed as affected, so the install base is in the hundreds of millions, and public internet scans routinely show very large numbers of exposed LDAP endpoints (ports 389/636), with domain…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news