LDAP: Microsoft Windows LDAP EncryptSslSend Use-After-Free

This signature detects attempts to exploit a known vulnerability against LDAP protocol. A successful attack can lead to arbitrary code execution.

Extended Description

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Affected Products

Microsoft windows_11_24h2

References

CVE: CVE-2024-49127

Short Name
LDAP:MS-SSL-SEND-UAF
Severity
Major
Recommended
True
Recommended Action
Drop
Category
LDAP
Keywords
CVE-2024-49127 EncryptSslSend LDAP Microsoft Use-After-Free Windows
Release Date
03/14/2025
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3791
Port
TCP/389
False Positive
Unknown
Vendors

Microsoft

Found a potential security threat?