CVE-2015-0240
10.0
CVSS v2.0 Base Score
90.70%
HIGH RiskEPSS (100th percentile)
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
Published: 2/24/2015
Modified: 5/6/2026
Vulnerability Summary
CVSS v2 Score
10
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS Score (Exploitation Probability)
90.70%HIGH Exploitation Risk
100th percentile
This vulnerability has a 90.70% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.