CVE-2015-2535
published 2015-09-09CVE-2015-2535: Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service…
PriorityP421medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
11.53%
95.5th percentile
Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service outage) by creating multiple machine accounts, aka "Active Directory Denial of Service Vulnerability."
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.1.22+dfsg-1 (bookworm) | samba 2:4.1.22+dfsg-1 (bookworm) |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 4.0.0 < 4.1.22 | 4.1.22 |
| samba | samba | >= 4.2.0 < 4.2.7 | 4.2.7 |
| samba | samba | >= 4.3.0 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mw8-88mv-4wcm: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2015-8467 [MEDIUM] CWE-269 GHSA-3mw8-88mv-4wcm: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
GHSA
GHSA-p89f-xm5w-cmgq: Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of se
ghsa_unreviewed·2022-05-14
CVE-2015-2535 [MEDIUM] GHSA-p89f-xm5w-cmgq: Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of se
Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service outage) by creating multiple machine accounts, aka "Active Directory Denial of Service Vulnerability."
OSV
CVE-2015-8467: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
osv·2015-12-29·CVSS 4.0
CVE-2015-8467 [MEDIUM] CVE-2015-8467: The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
Red Hat
samba: Denial of service attack against Windows Active Directory server.
vendor_redhat·2015-12-16·CVSS 4.0
CVE-2015-8467 [MEDIUM] samba: Denial of service attack against Windows Active Directory server.
samba: Denial of service attack against Windows Active Directory server.
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7
Debian
CVE-2015-8467: samba - The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/sam...
vendor_debian·2015·CVSS 4.0
CVE-2015-8467 [MEDIUM] CVE-2015-8467: samba - The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/sam...
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.
Scope: local
bookworm: resolved (fixed in 2:4.1.22+dfsg-1)
bullseye: resolved (fixed in 2:4.1.22+dfsg-1)
forky: resolved (fixed in 2:4.1.22+dfsg-1)
sid: resolved (fixed in 2:4.1.22+dfsg-1)
trixie: resolved (fixed in 2:4.1.22+dfsg-1)
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated CriticalMS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this month which affected Internet Explorer versions
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
## Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated Critical MS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this m
Bugzilla
CVE-2015-8467 samba: Denial of service attack against Windows Active Directory server.
bugzilla·2015-12-10·CVSS 4.0
CVE-2015-8467 [MEDIUM] CVE-2015-8467 samba: Denial of service attack against Windows Active Directory server.
CVE-2015-8467 samba: Denial of service attack against Windows Active Directory server.
As per samba upstream advisory:
Samba, operating as an AD DC, is sometimes operated in a domain with a mix of Samba and Windows Active Directory Domain Controllers.
All versions of Samba from 4.0.0 to 4.3.2 inclusive, when deployed as an AD DC in the same domain with Windows DCs, could be used to override the protection against the MS15-096 / CVE-2015-2535 security issue in Windows.
Prior to MS16-096 it was possible to bypass the quota of machine accounts a non-administrative user could create. Pure Samba domains are not impacted, as Samba does not implement the SeMachineAccountPrivilege functionality to allow non-administrator users to create new computer objects.
The following mitigation was sugge
2015-09-09
Published