CVE-2011-1786
published 2011-05-03CVE-2011-1786: lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware ESXi 4.1…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.01%
86.0th percentile
lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware ESXi 4.1 and ESX 4.1 and possibly other products, allows remote attackers to cause a denial of service (daemon crash) via an Active Directory login attempt that provides a username containing an invalid byte sequence.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| likewise | likewise_open | — | — |
| likewise | likewise_open | — | — |
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59fm-p4x5-qvjv: lsassd in Likewise Open /Enterprise 5
ghsa_unreviewed·2022-05-14
CVE-2011-1786 [MEDIUM] GHSA-59fm-p4x5-qvjv: lsassd in Likewise Open /Enterprise 5
lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware ESXi 4.1 and ESX 4.1 and possibly other products, allows remote attackers to cause a denial of service (daemon crash) via an Active Directory login attempt that provides a username containing an invalid byte sequence.
VMware
VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
vendor_vmware·2011-04-28·CVSS 7.8
CVE-2010-1323 [HIGH] VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
VMSA-2011-0007: VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
a. ESX/ESXi Socket Exhaustion By sending malicious network traffic to an ESXi or ESX host an attacker could exhaust the available sockets which would prevent further connections to the host. In the event a host becomes inaccessible its virtual machines will continue to run and have network connectivity but a reboot of the ESXi or ESX host may be required in order to be able to connect to the host again. ESXi and ESX hosts may intermittently lose connectivity caused by applications that do not correctly close sockets. If this occurs an error message similar to the following may be written to the vpxa log: socket() returns -1 (Cannot allocate memory) An error message
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://kb.vmware.com/kb/1035108http://lists.vmware.com/pipermail/security-announce/2011/000133.htmlhttp://secunia.com/advisories/44349http://securityreason.com/securityalert/8240http://securitytracker.com/id?1025452http://www.likewise.com/community/index.php/forums/viewannounce/1104_27/http://www.securityfocus.com/archive/1/517739/100/0/threadedhttp://www.securityfocus.com/bid/47625http://www.vmware.com/security/advisories/VMSA-2011-0007.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/67194http://kb.vmware.com/kb/1035108http://lists.vmware.com/pipermail/security-announce/2011/000133.htmlhttp://secunia.com/advisories/44349http://securityreason.com/securityalert/8240http://securitytracker.com/id?1025452http://www.likewise.com/community/index.php/forums/viewannounce/1104_27/http://www.securityfocus.com/archive/1/517739/100/0/threadedhttp://www.securityfocus.com/bid/47625http://www.vmware.com/security/advisories/VMSA-2011-0007.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/67194
2011-05-03
Published