Not Failing Securely ('Failing Open') in Microsoft Windows and Windows Server - CVE-2024-43532
Published: October 8, 2024 / Updated: October 23, 2024
Vulnerability details
The vulnerability allows a remote user to escalate privileges in Active Directory domain.
The vulnerability exists due to the way the Remote Registry client handles RPC authentication during certain fallback scenarios when SMB transport is unavailable. A remote user can authenticated against the AD server, intercept the NTLM authentication handshake from the client and forward it to another service, such as the (ADCS), and create a new domain administrator.
Successful exploitation of the vulnerability may allows a domain user to take over the entire AD.
Affected software
Windows Server
How to mitigate CVE-2024-43532
Windows Server - addressed in versions 2008 R2 6.1.7601.27366, 2008 6.0.6003.22918, 2012 R2 6.3.9600.22221, 2012 6.2.9200.25118, 2022 23H2 10.0.25398.1189, 2022 10.0.20348.2762