Impact
The vulnerability is a use‑after‑free flaw in the Apache HTTP Server mod_ldap module that is triggered by per‑directory configuration. The flaw may allow an attacker to trigger memory corruption during LDAP processing, which could result in arbitrary code execution or cause a denial of service. The weakness is identified as CWE‑416.
Affected Systems
Apache HTTP Server supplied by the Apache Software Foundation is affected from version 2.4.0 up to and including 2.4.67. Any installation using the mod_ldap module in per‑directory contexts within that version range is vulnerable.
Risk and Exploitability
EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so publicly observed exploitation frequency is unknown. The absence of an EPSS score also suggests that the exploit is not widely deployed yet. Due to the use‑after‑free nature, the attacker would need to craft a request that triggers mod_ldap in a per‑directory configuration; successful exploitation could allow arbitrary code execution on the web server with the privileges of the HTTPd process. The CVSS score is not supplied, but the potential impact is high, warranting immediate remediation.
OpenCVE Enrichment