Proof -of-concept exploit is now public for a vulnerability in Microsoft's Remote Registry (WinReg) client that could be used for an NTLM attack, compromising the security of the authentication process.
See also: Windows 10: Microsoft fixes Connected Cache bug

The vulnerability is tracked as CVE-2024-43532 and exploits an alternative mechanism in the Windows Registry client (WinReg) implementation that relies on old transport protocols if the SMB transport is not present.
An attacker who exploits the security issue could relay NTLM authentication to Active Directory Certificate Services (ADCS) to obtain a user certificate for further domain authentication.
The flaw affects all Windows Server versions 2008 through 2022, as well as Windows 10 and Windows 11.
CVE-2024-43532 stems from the way Remote Registry client handles RPC (Remote Procedure Call) authentication during certain alternative scenarios when SMB transport is unavailable.
See also: Hackers exploit vulnerability in Microsoft Defender to spread ACR, Lumma and Meduza Stealers
When this happens, the client switches to older protocols such as TCP/IP and uses a weak authentication level (RPC_C_AUTHN_LEVEL_CONNECT), which does not verify the authenticity or integrity of the connection.

An attacker could authenticate to the server and create new domain administrator accounts by intercepting the NTLM authentication handshake from the client and forwarding it to another service, such as (ADCS).
Successful exploitation of CVE-2024-43532 leads to a new way to perform an NTLM relay attack, one that leverages the WinReg component to transmit authentication details that could lead to domain takeover.
See also: Godeal24: Incredible discounts on Microsoft Office 2021 & Office 2024
Windows Server is a family of operating systems designed by Microsoft specifically for server management. Ideal for businesses of all sizes, Windows Server offers powerful solutions, including file and storage management, networking, and a suite of advanced security features to protect against threats. With support for cloud-based integrations, Windows Server enables seamless connectivity and resource sharing across devices and locations. The operating system is regularly updated to include the latest innovations in technology, ensuring it meets the demands of modern IT environments.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
