CVE-2015-8570: High severity adselfservice plus vulnerability
The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arbitrary domain user passwords via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8570?
CVE-2015-8570 is considered a high-severity vulnerability due to its potential to allow unauthorized password changes for domain users.
How do I fix CVE-2015-8570?
To fix CVE-2015-8570, ensure that you update to the latest version of Lepide Active Directory Self Service that addresses this vulnerability.
Who is affected by CVE-2015-8570?
CVE-2015-8570 affects users of Lepide Active Directory Self Service where remote authenticated users can exploit the password reset functionality.
What are the potential risks of CVE-2015-8570?
The risks of CVE-2015-8570 include unauthorized access to user accounts and potential data breaches due to compromised passwords.
Is there an exploit available for CVE-2015-8570?
Yes, an exploit for CVE-2015-8570 exists, allowing attackers to manipulate password reset requests to compromise user accounts.