CVE-2015-0240 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 88% (pctl 100)
Patch early
A public exploit exists.
Description
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 88.01% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-17 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-02-24 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| novell | suse linux enterprise desktop |
| novell | suse linux enterprise server |
| novell | suse linux enterprise software development kit |
| redhat | enterprise linux |
| samba | samba |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Samba < 3.6.2 (x86) - Denial of Service (PoC) | 2015-04-13 |
References
- http://advisories.mageia.org/MGASA-2015-0084.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00035.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html
- http://marc.info/?l=bugtraq&m=142722696102151&w=2
- http://marc.info/?l=bugtraq&m=143039217203031&w=2
- http://rhn.redhat.com/errata/RHSA-2015-0249.html
- http://rhn.redhat.com/errata/RHSA-2015-0250.html
- http://rhn.redhat.com/errata/RHSA-2015-0251.html
- http://rhn.redhat.com/errata/RHSA-2015-0252.html
- http://rhn.redhat.com/errata/RHSA-2015-0253.html
- http://rhn.redhat.com/errata/RHSA-2015-0254.html
- http://rhn.redhat.com/errata/RHSA-2015-0255.html
- http://rhn.redhat.com/errata/RHSA-2015-0256.html
- http://rhn.redhat.com/errata/RHSA-2015-0257.html
- http://security.gentoo.org/glsa/glsa-201502-15.xml
→ the Explorer · watch your stack · NVD