vendor:
Windows Server
by:
Todor Donev
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: Windows Server
Affected Version From: MS Windows Server 2008/2008 R2/ 2012/2012 R2/
Affected Version To: MS Windows Server 2016
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
MS Windows Server 2008/2008 R2/ 2012/2012 R2/ AD LDAP RootDSE Netlogon (CLDAP “AD Ping”) query reflection DoS PoC
The attacker sends a simple query to a vulnerable reflector supporting the Connectionless LDAP service (CLDAP) and using address spoofing makes it appear to originate from the intended victim. The CLDAP service responds to the spoofed address, sending unwanted network traffic to the attacker’s intended target. Amplification techniques allow bad actors to intensify the size of their attacks, because the responses generated by the LDAP servers are much larger than the attacker’s queries. In this case, the LDAP service responses are capable of reaching very high bandwidth and an average amplification factor of 46x and a peak of 55x has been seen.
Mitigation:
Disable the CLDAP service on the vulnerable server, or restrict access to the service from untrusted networks.