CVE-2024-37393: SQL Injection
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37393?
CVE-2024-37393 is classified as a high-severity vulnerability due to the potential for unauthenticated remote access and data exfiltration.
How do I fix CVE-2024-37393?
To fix CVE-2024-37393, upgrade SecurEnvoy MFA to version 9.4.514 or later where the vulnerabilities are addressed.
Who is affected by CVE-2024-37393?
CVE-2024-37393 affects users of SecurEnvoy Multi-factor Authentication Solutions versions prior to 9.4.514.
What type of attack does CVE-2024-37393 enable?
CVE-2024-37393 enables blind LDAP injection attacks, allowing attackers to exfiltrate data from Active Directory.
Can CVE-2024-37393 be exploited remotely?
Yes, CVE-2024-37393 can be exploited remotely by unauthenticated attackers.