Script kiddies beware!
Script kiddies beware!
Exploiting the #LDAPNightmare #Vulnerability: A Hidden Danger
https://technewsro.blog/exploatarea-vulnerabilitatii-ldapnightmare-un-pericol-ascuns/
În decembrie 2024, Microsoft a abordat două vulnerabilități critice în protocolul Windows Lightweight Directory Access Protocol (LDAP) prin lansarea lunară Patch Tuesday. Aceste vulnerabilități, CVE-2024-49112 și CVE-2024-49113, au fost considerate extrem de semnificative datorită utilizării pe scară largă a LDAP în mediile Windows.CVE-2024-49112 este o eroare de executare a codului la distanță (RCE) care permite
Résumé de la situation concernant les vulnérabilités CVE-2024-49113 (LDAPNightmare) & CVE-2024-49112 dans le service LDAP Windows
🔍 Les vulnérabilités en bref
⚡ CVE-2024-49112
⚡ CVE-2024-49113
💡 Clarifications importantes de Yuki Chen :
"Here is the ironic side of vuln response based on CVSS score - especially when it comes to binary vulns. Everyone cares about CVE-2024-49112 because MS assigns CVSS 9.8 to this vulnerability, but never forget the score is highly affected by the skills of the analysis team behind."
— Yuki Chen
🔗 Source : Tweet de Yuki Chen
🛡️ Exploitation potentielle de CVE-2024-49112 (méthodes pas encore rendues publiques)
🎯 Sur un contrôleur de domaine
👨💻 Sur un client LDAP
🔗 Source : TrendMicro
Comment les attaquants peuvent exploiter CVE-2024-49113 (LDAPNightmare)
🔗 PoC CVE-2024-49113 (LDAPNightmare) : GitHub SafeBreach-Labs
🔒 Comment se protéger
LDAPNightmare, a PoC exploit targets Windows LDAP flaw CVE-2024-49113
https://securityaffairs.com/172618/security/ldapnightmare-exploit-cve-2024-49113.html
#Infosec #Security #Cybersecurity #CeptBiro #LDAPNightmare #PoCexploit #WindowsLDAP
LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers
https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html
#Infosec #Security #Cybersecurity #CeptBiro #LDAPNightmare #PoCExploit #LSASS #WindowsDomainControllers
LDAP Nightmare : l’attaque qui fait trembler Windows Server et l’Active Directory ! Patchez !
https://www.it-connect.fr/ldap-nightmare-attaque-fait-trembler-windows-server-et-active-directory/
#Infosec #Security #Cybersecurity #CeptBiro #LDAPNightmare #Attaque #WindowsServer #ActiveDirectory