Start with Identity
Protocol · 2 briefs

LDAP identity CVEs

LDAP is how almost every on-prem identity integration still binds. A crash or RCE on the DC LDAP stack is an authentication outage, then a domain-compromise candidate.

How this protocol fails

LDAPNightmare and its critical sibling (December 2024) showed that a crafted LDAP response can take a domain controller down, and worse. Public PoCs kept this in the 2025 defender window. Vault and Okta LDAP auth methods also failed lockout, MFA, and enumeration checks. The protocol is old. The bind is still load-bearing.

What security people should do

  • Confirm the December 2024 Windows LDAP updates on every DC and management jump box.
  • Restrict which hosts a DC will chase for referrals. Prefer LDAPS.
  • If Vault or Okta delegates to LDAP, take those product CVEs in the same change. Enumeration plus lockout bypass is a brute-force pair.

CVEs in this category

2
LDAP
0
On CISA KEV
0
Actively exploited
2
Showing
Severity
Year
Status

Showing 2 of 2

Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.