Body Background
TrendAI™ Zero Day Initiative™ Logo

Lepide Active Directory Self Service Arbitrary User Password Change Domain Privilege Escalation Vulnerability

December 8th, 2015

Vulnerability Details


This vulnerability allows domain users to reset arbitrary account passwords on vulnerable installations of Lepide Active Directory Self Service. No user interaction is required to exploit this vulnerability.

The specific flaw exists within processing of the password reset functionality of Active Directory Self Service. A user should only be able to change the password of other users who have explicitly delegated that power to him. By crafting request packets to the Lepide web service, a domain user can change the password of any user in the Active Directory domain. A malicious user can use this to appropriate the account of a Domain Administrator.

Additional Details

Lepide has issued an update to correct this vulnerability. More details can be found at:
http://www.lepide.com/active-directory-self-service/

Disclosure Timeline

  • 2015-08-20 - Vulnerability reported to vendor
  • 2015-12-08 - Coordinated public release of advisory

Credit

Alain Homewood

Back to Advisories

Hero Background

Stand at the front line of proactive security

Trend ZDI connects the experts who discover, remediate, and defend.
Add your voice to the work that pushes attackers back.