# LDAPNightmare, domain-controller DoS via crafted LDAP response

Source: https://startwithidentity.com/cves/cve-2024-49113/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Windows LDAP client code could be crashed by a crafted LDAP response. Against a domain controller, that is an authentication outage. SafeBreach published a public PoC in January 2025 under the name LDAPNightmare. Microsoft patched in December 2024. [CVE-2024-49112](https://startwithidentity.com/cves/cve-2024-49112/) is the related critical LDAP RCE-class sibling.

## Why it matters

LDAP is how almost every on-prem identity integration still binds. Taking the DC's LDAP client (or the DC itself) offline is an identity incident: SSO fails, lockouts spike, and help desks get phished. A public PoC in January 2025 kept this in the 2025 defender window.

## What to do

- Confirm December 2024 LDAP updates are on every DC and management jump box.
- Restrict which hosts a DC will accept LDAP referrals and callbacks from.
- Watch for sudden LSASS / LDAP-client crashes after a referral to an unknown host.

## After you patch

Directory service flaws reach the system that answers "who is this" for everything else, so scope the response to the directory rather than the host.

- **Review privileged group membership and delegation rights** for changes during the exposure window.
- **Rotate service account credentials** used for directory binds, which are frequently stored in plaintext in application configuration. See [service account](https://startwithidentity.com/glossary/service-account/).
- **Check for newly created accounts and computer objects**, the standard persistence step after directory access.
- **Confirm LDAP signing and channel binding** are enforced, since relay attacks against unsigned binds are the recurring follow-on. See [lateral movement](https://startwithidentity.com/glossary/lateral-movement/).

## Sources

- [NVD: CVE-2024-49113](https://nvd.nist.gov/vuln/detail/CVE-2024-49113)
- SafeBreach, LDAPNightmare PoC, January 2025
