Interesting Exploit for a critical Windows vulnerability has been published: just one request is enough to destroy any infrastructure

abadon1969

Moderator
Staff member
MODERATOR
SUPREME
MEMBER
Joined
Sep 17, 2025
Messages
626
Reaction score
4,272
Deposit
0$
😂 Exploit for a critical Windows vulnerability has been published: just one request is enough to destroy any infrastructure

A proof-of-concept exploit for a vulnerability in the Windows Lightweight Directory Access Protocol (LDAP), patched in December 2024, was recently published online.

The vulnerability, designated CVE-2024-49113 (CVSS 7.5), can lead to a denial of service (DoS). Its fix was included in Microsoft's December updates, along with CVE-2024-49112 (CVSS 9.8), a critical integer overflow vulnerability that allows remote code execution.

⚠️ A proof-of-concept exploit, dubbed "LDAPNightmare" by SafeBreach Labs researchers, can crash a Windows server without any additional conditions if the domain controller's (DC) DNS server has internet access.
 
𝙷𝚎𝚕𝚕𝚘 𝙸’𝚟𝚎 𝙶𝚘𝚝 𝙷𝚒𝚐𝚑 𝚀𝚞𝚊𝚕𝚒𝚝𝚢 𝙲𝚊𝚛𝚍𝚜 𝚆𝚑𝚒𝚌𝚑 𝙻𝚒𝚗𝚔𝚜 𝙰𝚞𝚝𝚘𝚖𝚊𝚝𝚒𝚌 𝚆𝚒𝚝𝚑𝚘𝚞𝚝 𝙾𝚃𝙿 𝚟𝚎𝚛𝚒𝚏𝚒𝚌𝚊𝚝𝚒𝚘𝚗: 𝙲𝚊𝚛𝚍 𝙲𝚊𝚗 𝙱𝚎 𝗎𝗌𝖾𝖽 𝖿𝗈𝗋 𝖲𝗁𝗈𝗉𝗉𝗂𝗇𝗀 , 𝖡𝗂𝗅𝗅𝗌 𝗉𝖺𝗒𝗆𝖾𝗇𝗍 ,𝖡𝗈𝗈𝗄𝗂𝗇𝗀𝗌 ,𝖦𝗂𝖿𝗍 𝖼𝖺𝗋𝖽𝗌
𝖮𝗇𝗅𝗂𝗇𝖾 𝖼𝖺𝗌𝗂𝗇𝗈 𝗉𝖺𝗒𝗆𝖾𝗇𝗍 𝖺𝗇𝖽 𝖼𝖺𝗇 𝖻𝖾 𝗎𝗌𝖾𝖽 𝖿𝗈𝗋 𝖢𝖺𝗌𝗁𝗈𝗎𝗍 𝗈𝗇 ….. 𝖢𝖺𝗌𝗁 𝖠𝗉𝗉 , 𝖠𝗉𝗉𝗅𝖾 𝖯𝖺𝗒 , 𝖯𝖺𝗒𝖯𝖺𝗅 , 𝖦𝖯𝖺𝗒 , 𝖶𝖴 , 𝖬𝗈𝗇𝖾𝗒𝖦𝗋𝖺𝗆 , 𝖵𝖾𝗇𝗆𝗈 & 𝖹𝖾𝗅𝗅𝖾

𝖳𝖾𝗅𝖾: @𝗄𝗋𝖺𝗇𝖾𝟣𝟤𝟥

Channel :https://t.me/+9A8WEfC5-DEyMWYx
 
Top Bottom