First published: Thu Jun 16 2016(Updated: )
Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft Windows Server 2012 x64 | =gold | |
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2012 x64 | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3226 is classified as a denial of service vulnerability.
To mitigate CVE-2016-3226, ensure that you apply the relevant security updates provided by Microsoft.
CVE-2016-3226 affects remote authenticated users on Microsoft Windows Server 2008 R2 SP1 and Windows Server 2012.
An attacker can cause a denial of service by creating a large number of machine accounts on the affected servers.
Yes, CVE-2016-3226 can be exploited by authenticated users with minimal skill.