← Back to browse · API

CVE-2024-37393

Severity
CRITICAL
CVSS
9.8
EPSS
0.03304
Risk score
40.36
CISA KEV
No
PoC
No
Published
2024-06-10
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-36632, GHSA-M2CR-JXG8-PR4V
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-36632

Description

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

References