PT-2024-6729 · Microsoft · Windows Netlogon+1
Paul Miller
·
Published
2024-10-08
·
Updated
2026-01-17
·
CVE-2024-38124
CVSS v3.1
9.0
Critical
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Windows Netlogon (affected versions not specified)
Description:
The vulnerability in Windows Netlogon is related to deficiencies in the authentication procedure, allowing a remote attacker to elevate their privileges. It involves predicting the name of a new domain controller, which can be easy in some domains, and potentially allows adversaries to escalate to Domain Admin. The issue is critical and can affect the system, with low complexity and no user interaction needed.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider implementing monitoring for any suspicious renaming activities of computers within the network.
Restrict access to sensitive areas of the network to minimize the risk of exploitation.
Avoid using potentially vulnerable authentication procedures until the issue is resolved.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Netlogon