CVE-2011-2014Improper Authentication in Microsoft Windows Server 2008

Severity
9.0CRITICALNVD
OSV7.5OSV5.9
EPSS
9.5%
top 7.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 8
Latest updateMay 13

Description

The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leve

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages3 packages

Ubunturedhat/libvirt< 1.2.2-0ubuntu13.1.16
Ubuntubusybox/busybox< 1:1.21.0-1ubuntu1.4+2

🔴Vulnerability Details

3
GHSA
GHSA-qm9j-69fp-v8p4: The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory2022-05-13
OSV
busybox vulnerabilities2019-04-03
OSV
libvirt vulnerabilities2016-01-12

💥Exploits & PoCs

4
Exploit-DB
Ubisoft Rayman Legends 1.2.103716 - Remote Stack Buffer Overflow (PoC)2014-06-18
Exploit-DB
PCMan FTP Server 2.07 - 'ABOR' Remote Buffer Overflow2014-01-29
Exploit-DB
Apache - Denial of Service2011-12-09
Exploit-DB
Apache - Remote Memory Exhaustion (Denial of Service)2011-08-19

📋Vendor Advisories

1
Red Hat
nginx: SMTP STARTTLS plaintext injection flaw2014-08-05

📐Framework References

1
CWE
Improper Check for Certificate Revocation

📄Research Papers

1
CTF
hashes / README2014

💬Community

4
Bugzilla
gcc: resource consumption issue in libstdc++ C++ regex library2014-08-05
Bugzilla
gcc: memory corruption issues in libstdc++ C++ regex library2014-08-05
Bugzilla
CVE-2014-4978 rawstudio: Insecure use of temporary file2014-07-16
Bugzilla
CVE-2014-0104 fence-agents: no verification of remote SSL certificates2014-02-28