# Windows LDAP critical remote-code-execution class flaw

Source: https://startwithidentity.com/cves/cve-2024-49112/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

CVE-2024-49112 is the critical Windows LDAP flaw that shipped next to [LDAPNightmare](https://startwithidentity.com/cves/cve-2024-49113/). CVSS 9.8. Same December 2024 patch train. Public discussion has treated it as RCE-class on the LDAP stack.

## Why it matters

A critical LDAP bug on a DC is a domain-compromise candidate, not a "directory availability" ticket. Take it with 49113, not after.

## What to do

- Verify the December 2024 LDAP updates by KBN, not by "we patched that month."
- Keep LDAPS-only where you can, and do not let DCs chase LDAP referrals to untrusted hosts.

## After you patch

Directory service flaws reach the system that answers "who is this" for everything else, so scope the response to the directory rather than the host.

- **Review privileged group membership and delegation rights** for changes during the exposure window.
- **Rotate service account credentials** used for directory binds, which are frequently stored in plaintext in application configuration. See [service account](https://startwithidentity.com/glossary/service-account/).
- **Check for newly created accounts and computer objects**, the standard persistence step after directory access.
- **Confirm LDAP signing and channel binding** are enforced, since relay attacks against unsigned binds are the recurring follow-on. See [lateral movement](https://startwithidentity.com/glossary/lateral-movement/).

## Sources

- [NVD: CVE-2024-49112](https://nvd.nist.gov/vuln/detail/CVE-2024-49112)
