Unrated severityNVD Advisory· Published Jun 10, 2024· Updated Aug 2, 2024
CVE-2024-37393
CVE-2024-37393
Description
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- SecurEnvoy/MFAdescription
- Range: <9.4.514
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.