High severity7.5NVD Advisory· Published Jun 10, 2024· Updated Jun 17, 2026
CVE-2024-37393
CVE-2024-37393
Description
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <9.4.514
- SecurEnvoy/MFAdescription
- cpe:2.3:a:securenvoy:multi-factor_authentication_solutions:*:*:*:*:*:*:*:*Range: <9.4.514
Patches
Vulnerability mechanics
References
3- learn.microsoft.com/en-us/openspecs/windows_protocols/ms-ada2/ad2ce8fa-42a0-4371-ad18-5d1d1c488b22nvdExploit
- www.optistream.io/blogs/tech/securenvoy-cve-2024-37393nvdExploitThird Party Advisory
- securenvoy.com/support/nvdProduct
News mentions
0No linked articles in our index yet.