PT-2024-6729 · Microsoft · Windows Netlogon+1

Paul Miller

·

Published

2024-10-08

·

Updated

2026-01-17

·

CVE-2024-38124

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows Netlogon (affected versions not specified)
Description: The vulnerability in Windows Netlogon is related to deficiencies in the authentication procedure, allowing a remote attacker to elevate their privileges. It involves predicting the name of a new domain controller, which can be easy in some domains, and potentially allows adversaries to escalate to Domain Admin. The issue is critical and can affect the system, with low complexity and no user interaction needed.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider implementing monitoring for any suspicious renaming activities of computers within the network. Restrict access to sensitive areas of the network to minimize the risk of exploitation. Avoid using potentially vulnerable authentication procedures until the issue is resolved.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-07942
CVE-2024-38124

Affected Products

Windows
Windows Netlogon