We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.
Reserved 2024-06-07 | Published 2024-06-10 | Updated 2024-08-02 | Assigner mitrewww.optistream.io/blogs/tech/securenvoy-cve-2024-37393
learn.microsoft.com/.../ad2ce8fa-42a0-4371-ad18-5d1d1c488b22
Support options