Exploiting LDAPNightmare PoC causes LSASS to crash and reboot Windows Domain Controllers

An exploit showcasing a proof-of-concept (PoC) has surfaced targeting a previously patched vulnerability affecting Windows Lightweight Directory Access Protocol (LDAP), which has the potential to initiate a denial-of-service (DoS) scenario.

An exploit showcasing a proof-of-concept (PoC) has surfaced targeting a previously patched vulnerability affecting Windows Lightweight Directory Access Protocol (LDAP), which has the potential to initiate a denial-of-service (DoS) scenario. The security loophole involving out-of-bounds reads has been identified as CVE-2024-49113 (CVSS score: 7.5). Microsoft addressed this issue within the December 2024 Patch Tuesday updates, along with CVE-2024-49112 (

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.