LDAPNightmare is a Windows Lightweight Directory Access Protocol (LDAP) denial-of-service vulnerability affecting unpatched Windows domain controllers. Public reporting describes the issue as reachable without authentication or user interaction and capable of crashing the target domain controller, disrupting Active Directory-dependent operations. The vulnerability is associated with Windows LDAP handling on domain controllers and was addressed by Microsoft in the December 2024 security updates.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a small standalone Python proof-of-concept for CVE-2024-49113 ('LDAP Nightmare') plus a detailed README. The exploit is not part of a larger framework. The main file, exploit.py, implements a malicious LDAP server that listens by default on TCP port 389 and constructs BER-encoded LDAP responses manually. Helper functions encode BER lengths, sequences, integers, octet strings, and enumerated values, then assemble LDAP messages. The exploit logic builds a normal-looking bind response and a crafted Search Result Entry containing a manipulated octet-string length field (default 0xFFFF) with much shorter actual data. This malformed response is intended to trigger a heap-based buffer overflow in the Windows LDAP client library wldap32.dll when a vulnerable Windows host initiates an LDAP query to the attacker-controlled server. The code appears to be a PoC/operational crash-or-trigger server rather than a full weaponized RCE chain: it has configurable listener IP/port and payload size, uses threading to handle multiple inbound clients, and focuses on delivering the malformed protocol response, but it does not include shellcode, a reverse shell, persistence, or automated victim coercion. The README documents affected Microsoft Windows Server and Windows client versions prior to December 2024 patches, explains the vulnerability mechanics, describes prerequisites such as victim connectivity to attacker TCP/389, and includes mitigation references and registry hardening guidance.
This repository is a Python proof-of-concept exploit for CVE-2024-49113, targeting a Windows LDAP/Netlogon denial-of-service condition. The code is not part of a common exploit framework. Repository structure is small and focused: LdapNightmare.py is the main entry point, rpc_call.py performs the outbound Netlogon RPC call using Impacket, exploit_server.py implements an attacker-controlled UDP LDAP server using asyncio and ldaptor, logger.py provides console logging, and requirements.txt lists dependencies. Operational flow: the main script starts a local UDP LDAP server on a configurable listen port (default 389), waits briefly, then connects to the target over DCERPC using ncacn_ip_tcp to the specified target IP and port (default 49664). It binds to the NRPC interface and invokes DsrGetDcNameEx2 with attacker-supplied DomainName, AccountName, and SiteName values. When the target subsequently sends an LDAP request to the attacker-controlled server, the PoC parses the request and returns a crafted LDAP SearchResultDone referral packet. The packet is intentionally manipulated at the BER level, including a referral result code and a hardcoded referral URL, to trigger the vulnerable behavior. The script treats a ConnectionResetError after the RPC call as success, based on the expectation that Netlogon runs inside lsass.exe and the vulnerable service will reset/crash when triggered. Main exploit capability: remote unauthenticated network-triggered denial of service against vulnerable Windows systems. There is no post-exploitation, persistence, credential theft, or remote code execution payload. The payload is a malicious LDAP referral response only. Because the exploit includes a working trigger path and hardcoded malicious response logic but no customizable offensive payload, the maturity is best classified as OPERATIONAL rather than mere POC or weaponized.
This repository provides a Metasploit-compatible exploit module for CVE-2024-49113, a critical vulnerability in the Windows LDAP client. The main file, 'ldapnightmare.py', is a Python script that sets up a malicious LDAP server and triggers the vulnerability on a target Windows system via a crafted DsrGetDcNameEx2 RPC call. The exploit requires the attacker to control a domain with specific DNS SRV records pointing to their LDAP server. When the target system connects and processes the malicious LDAP referral response, it causes a denial-of-service condition, resulting in a system restart. The repository includes a README with detailed usage instructions, configuration options, and references to the original research. The code is operational and integrates with the Metasploit Framework, but the payload is hardcoded and not easily customizable, making it an OPERATIONAL-level exploit. No fake or detection-only scripts are present; the code is a genuine exploit for the specified CVE.
This repository provides a proof-of-concept exploit for CVE-2024-49113, a critical vulnerability in the Windows LDAP client that can be triggered remotely to crash (DoS) a Windows Server. The main entry point is 'LdapNightmare.py', which orchestrates the attack by starting a malicious LDAP server (on a configurable UDP port, default 389) and then using the Netlogon Remote Protocol (NRPC) to instruct the target server to connect to the attacker's LDAP server. The exploit requires the attacker to control a domain name with specific DNS SRV records pointing to the attacker's machine. When the victim server queries the attacker's LDAP server, a specially crafted LDAP referral response is sent (implemented in 'exploit_server.py'), which triggers the vulnerability and causes the target to crash. The code is written in Python and uses the 'ldaptor' and 'impacket' libraries. The repository includes supporting modules for logging and RPC calls, as well as setup instructions and technical background in the README. No weaponized or post-exploitation payload is included; the exploit demonstrates denial-of-service capability only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows LDAP vulnerability mentioned as a prior example of fake PoC lures targeting researchers, not the main subject of this report.
A Windows LDAP out-of-bounds read vulnerability that can be exploited for denial-of-service (LSASS crash / domain controller reboot).
A Windows Domain Controller denial-of-service vulnerability in the LDAP/CLDAP client referral handling path that can be triggered remotely without authentication, leading to LSASS crash and system crash/reboot.
A denial of service vulnerability in Windows LDAP.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.