SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-0240

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute…

HIGH 10.0EPSS 87.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 87.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
87.64% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-17
Affected
redhat/enterprise linux · samba/samba · novell/suse linux enterprise desktop · novell/suse linux enterprise server · novell/suse linux enterprise software development kit · canonical/ubuntu linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.