THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-37393

Reserved:2024-06-07
Published:2024-06-10
Updated:2024-06-12

Description

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

References

https://securenvoy.com/support/

https://www.optistream.io/blogs/tech/securenvoy-cve-2024-37393

https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-ada2/ad2ce8fa-42a0-4371-ad18-5d1d1c488b22

cve.org CVE-2024-37393

nvd.nist.gov CVE-2024-37393

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-37393