Skip to content
CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability Remote Authentication Dial-In User Service

CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability Remote Authentication Dial-In User Service

Written By Anoop C Nair
Last Updated August 19, 2024
Posted In Windows
SHARE

It is essential to know about a security risk, CVE-2024-3596, in the Remote Authentication Dial-In User Service RADIUS protocol related to MD5 hashing. MD5 is a cryptographic hash function algorithm that converts input data of any length into a fixed 128-bit (16-byte) hash value.

MD5 is a hashing method used to secure data. However, different pieces of data can produce the same hash value, known as a collision. This issue is especially concerning for RADIUS traffic sent over the Internet using UDP or User Datagram Protocol.

UDP is one of the core protocols of the Internet Protocol (IP) suite. It does not check if data is altered, so if an attacker exploits the MD5 collision problem, they can change the data packets. This can lead to unauthorized access or other security issues.

To take advantage of this security risk, an attacker must be on the same network as the RADIUS server and have access to it. However, if the RADIUS traffic is sent through a VPN (Virtual Private Network), the VPN secures the data and prevents tampering, so this risk does not apply.

Patch My PC

What is the Security Risk Related to the RADIUS Protocol?


The security risk involves MD5 collision issues that affect RADIUS traffic sent over the internet using the User Datagram Protocol (UDP).

Does this Security Risk Affect all RADIUS Environments?


No, This risk requires physical access to the RADIUS network and the Network Policy Server (NPS).

New RADIUS Standard and Potential NPS Connection Failures with July 2024 Windows Updates

Starting July 9, 2024, Windows updates support a new security feature called the Message-Authenticator attribute in RADIUS Access-Request packets. This is required by new RADIUS standards. While this update improves security, it might cause connection issues with the Network Policy Server (NPS) if your firewall or RADIUS system doesn’t support this feature.

  • The update doesn’t cause these issues directly; they happen only if your current setup is incompatible.
Security Risks in CVE-2024-3596 Remote Authentication Dial-In User Service RADIUS Protocol - Fig.1 - Creds to MS
Security Risks in CVE-2024-3596 Remote Authentication Dial-In User Service RADIUS Protocol – Fig.1 – Creds to MS

Workaround or Actions to Secure Your RADIUS Environment

KB5040268 provides detailed guidance on managing the vulnerability associated with CVE-2024-3596. It involves an attack on Access-Request packets in the RADIUS protocol. This vulnerability, related to MD5 collisions, poses a risk where data packets can be altered during transit.

Implementing specific configurations and workarounds is essential to secure your RADIUS environment. The table below provides more details.

Secure Your RADIUS EnvironmentWorkaround or Actions
Enable Message-Authenticator for RequestsIt is important to ensure that all Access-Request packets include the Message-Authenticator attribute. This feature is turned off by default, so make sure to activate it.
Verify Message-Authenticator in RequestsYou should confirm that Access-Request packets contain the Message-Authenticator attribute. It is advisable to enforce this requirement for all packets. By default, this setting is off, so you should enable it.
Check Message-Authenticator with Proxy-StateIf you use the Proxy-State attribute, consider enabling the limitProxyState option. This will drop packets with the Proxy-State attribute if they do not also include the Message-Authenticator attribute. This option is off by default, so it’s recommended to turn it on if you cannot validate every packet.
Verify Message-Authenticator in ResponsesYou must ensure that RADIUS response packets (Access-Accept, Access-Reject, and Access-Challenge) include the Message-Authenticator attribute. Enable the requireMsgAuth option to discard response packets from remote servers that lack this attribute. This setting is off by default, so turn it on to enhance security.
Security Risks in CVE-2024-3596 Remote Authentication Dial-In User Service RADIUS Protocol – Table 1

CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability

CVE-2024-3596 is a security vulnerability in the RADIUS protocol identified by CERT/CC. This vulnerability is classified as important due to its potential impact on spoofing. The table below provides more details.

CVE DetailsData
CVE TitleCERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability
CVE IDCVE-2024-3596
Release DateJuly 9, 2024
Assigning CNACERT/CC
ImpactSpoofing
Max SeverityImportant
WeaknessCWE-327: Use of a Broken or Risky Cryptographic Algorithm
CVSS SourceMicrosoft
CVSS Score7.5 / 6.5
Security Risks in CVE-2024-3596 Remote Authentication Dial-In User Service RADIUS Protocol – Table 2
Security Risks in Remote Authentication Dial-In User Service RADIUS Protocol - Fig.2 - Creds to MS
Security Risks in CVE-2024-3596 Remote Authentication Dial-In User Service RADIUS Protocol – Fig.2 – Creds to MS

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update

Key Takeaways BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update! After deploying the June 2026 Windows update (KB5094126), some HP EliteDesk 800 G6 devices began prompting for the BitLocker recovery key after every reboot. Based on our investigation, the Secure Boot UEFI 2023 certificate update does not appear to be […]

AC Anoop C Nair 5 min read
Microsoft Defender for Endpoint

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Key Takeaways In this post, we are discussing how Microsoft Defender for Endpoint EDR Updates Will Be Delivered Through Microsoft Update. Microsoft has introduced a new update model for Microsoft Defender for Endpoint Detection and Response (EDR) security updates. Previously, these updates were included with the monthly Windows security updates. This change enables Microsoft to […]

AC Anoop C Nair 5 min read