Skip to main content

CVE-2015-0240

10.0
CVSS v2.0 Base Score
90.70%
HIGH RiskEPSS (100th percentile)

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

Published: 2/24/2015
Modified: 5/6/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

10

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

90.70%HIGH Exploitation Risk
100th percentile

This vulnerability has a 90.70% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification