
CVE-2024-49112 LDAP RCE PoC and Metasploit Module
CVE-2024-49112 LDAP RCE PoC and Metasploit Module
Edit: links updated (last 3 copies to go)
Link to Download:
You can reach me at: [email protected] please dont ask me if I can provide this for free, or if I can test your target, or how to add the module to metasploit(google it please). what I can offer?: if you need any help with setting up the python version (I can guide). if you need help with the analyze (I can answer you questions regarding the analyze via email).
The Windows Lightweight Directory Access Protocol (LDAP) service is vulnerable to an integer overflow, which can lead to unauthenticated remote code execution (RCE). This vulnerability allows attackers to execute arbitrary code on a vulnerable system. here, we focus on exploiting the LDAP server-side vulnerability (unauthenticate and no user interaction).
This vulnerability exists in both the LDAP server and the LDAP client. However, exploiting these components requires different approaches. here, we will focus on exploitation of the LDAP server, which can be targeted directly to achieve RCE without any user interaction.
I will include all my findings and technical details regarding the above mentioned component
with the python script showed below in the video PoC and the custom metasploit module which
I wrote for this to make it easier for post exploitations.
You can view PoC video here:
.