PT-2025-29115 · Apache+2 · Apache Http Server+2
CVE-2024-43394
·
Publicado
2025-07-10
·
Atualizado
2025-12-26
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache HTTP Server versions 2.4.0 through 2.4.63
Description:
A Server-Side Request Forgery (SSRF) issue exists in Apache HTTP Server on Windows. This issue potentially allows the leakage of NTLM hashes to a malicious server via
mod rewrite or Apache expressions that process unvalidated request input. The server offers limited protection against administrators directing it to open UNC paths. Windows servers should limit the hosts they will connect to over SMB based on the nature of NTLM authentication.Recommendations:
Update to a version later than 2.4.63.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Http Server
Red Os
Windows