@FritzAdalis@infosec.exchange @cR0w@infosec.exchange It's a little more complicated (and I have no means to verify the purported PoC, but it looks legit-ish), but apparently you can crash LSASS by sending a CLDAP DC locator ping packet with the username being Ax130 or longer. Code execution seems possible (according to MSRC), but the PoC is just a DoS.