We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-37393



Description

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

Reserved 2024-06-07 | Published 2024-06-10 | Updated 2024-08-02 | Assigner mitre

References

securenvoy.com/support/

www.optistream.io/blogs/tech/securenvoy-cve-2024-37393

learn.microsoft.com/.../ad2ce8fa-42a0-4371-ad18-5d1d1c488b22

cve.org (CVE-2024-37393)

nvd.nist.gov (CVE-2024-37393)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-37393

Support options

Helpdesk Chat, Email, Knowledgebase