Win-DDoS Exploits Domain Controllers for DDoS Attacks

22 Aug 2025

SafeBreach researchers have uncovered a novel method, Win-DDoS, enabling attackers to exploit public domain controllers as agents for distributed denial-of-service (DDoS) attacks. This technique leverages multiple vulnerabilities within Windows Active Directory domain controllers (DCs), successfully turning them into unwilling participants in overwhelming targeted servers with malicious traffic.

Win-DDoS exploits domain controllers for DDoS attacks

Understanding the Vulnerabilities

The vulnerabilities, including CVE-2025-32724, represent significant security risks where attackers can essentially hijack the server's resources without requiring credentials. These flaws allow unauthorized users to remotely crash publicly accessible systems and manipulate internal infrastructure. SafeBreach found four vulnerabilities, with CVE-2025-32724 identified as a zero-click threat that can be leveraged for DDoS.

Other vulnerabilities cover uncontrolled resource consumption within Windows LDAP and Windows Netlogon, such as CVE-2025-26673 and CVE-2025-49716, which allow similar denial-of-service attacks. Additionally, CVE-2025-49722 affects Print Spooler components, crashing domain controllers and related systems.

The Attack Mechanism

Win-DDoS operates through a sophisticated series of interactions. Attackers send specially crafted RPC calls to accessible DCs, causing them to function as CLDAP clients. These clients are directed to an attacker's CLDAP server, which subsequently issues an LDAP referral to another malicious server. This server delivers an extensive list of LDAP URLs, all resolving to the victim's IP and port.

This series of LDAP queries, initiated by the DCs upon these referrals, generates what can be described as 'volumetric' traffic that significantly impacts the victim server. Many services close down non-HTTP LDAP packets; however, domain controllers continue to send queries as instructed by the attacker's referrals.

Mitigations and Recommendations

The researchers from SafeBreach, namely Or Yair and Shahak Morag, strongly advise organizations to immediately install patches released by Microsoft for Windows Server and Active Directory. These updates, issued in the months of April, June, and July 2025, are crucial for mitigating the risks posed by these vulnerabilities.

Furthermore, SafeBreach suggests companies assume that all servers and endpoints are potential targets for DDoS attacks, irrespective of whether they face publicly or are strictly internal. They recommend deploying effective detection and defense mechanisms, along with rapid identification strategies for attack sources to strengthen defensive postures against Win-DDoS threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6393640
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1273723
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
495679
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453650
downloads

News and reviews for Desktop Windows

Curly COMrades Exploit Hyper-V for Security Bypasses

Curly COMrades use Microsoft Hyper-V to bypass security defenses and execute attacks. Identified in collaboration with the Georgian CERT.

Read more

Arc Raiders and Battlefield 6 Excel in Performance and Accessibility

Arc Raiders and Battlefield 6 attract players with strong performance, low system requirements. Gamer engagement sees boost in 2025.

Read more

Optimizing Arc Raiders: Best PC Settings for Performance

Boost Arc Raiders performance on PC with optimized settings for graphics and audio. Key changes include Nvidia configurations and frame rate tweaks.

Read more

Hyper-V Exploited for Covert Linux Malware on Windows Systems

Russian group Curly COMrades uses Hyper-V to deploy Linux malware on Windows, hiding it from detection.

Read more

Phasmophobia: Expanded Gameplay Offers Unique Challenges

Phasmophobia enriches ghost-hunting with new maps and features, promising a fresh experience for horror fans.

Read more

Roadside Research Combines Alien Simulation with Business Strategy

Roadside Research, released 2025-11-04, lets players manage a gas station as an alien. It blends simulation and research in a strategic game.

Read more

Warhammer Survivors Expands Roguelike Genre in 2026

Warhammer Survivors, a roguelike by Auroch Digital and Poncle, launches in 2026 with Warhammer lore, new characters, and modes.

Read more

Malicious Clones Target Flyoobe Windows 11 Bypass Tool

Flyoobe warns users about malicious clones of its Windows 11 bypass tool. Protect your device by downloading only from official sources.

Read more

Pillars of Eternity Introduces New Turn-Based Mode

Obsidian unveils Pillars of Eternity's turn-based mode, launching beta on 2023-11-05. Aims at improved gameplay flexibility.

Read more

Arc Raiders Adds New Social Dynamics in Solo Queue

Arc Raiders players find success through communication in solo queue, transforming gameplay with increased cooperation and engagement.

Read more