First published: Tue Dec 15 2015(Updated: )
The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arbitrary domain user passwords via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8570 is considered a high-severity vulnerability due to its potential to allow unauthorized password changes for domain users.
To fix CVE-2015-8570, ensure that you update to the latest version of Lepide Active Directory Self Service that addresses this vulnerability.
CVE-2015-8570 affects users of Lepide Active Directory Self Service where remote authenticated users can exploit the password reset functionality.
The risks of CVE-2015-8570 include unauthorized access to user accounts and potential data breaches due to compromised passwords.
Yes, an exploit for CVE-2015-8570 exists, allowing attackers to manipulate password reset requests to compromise user accounts.