CVE-2016-3226High
Active Directory Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A denial of service vulnerability exists in Active Directory when an authenticated attacker creates multiple machine accounts. An attacker who successfully exploited this vulnerability could cause the Active Directory service to become nonresponsive. To exploit this vulnerability, an attacker must have valid credentials. An attacker could exploit this vulnerability by creating multiple machine accounts, resulting in denial of service. The update addresses the vulnerability by correcting how machine accounts are created.
🎯 Affected products6
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
✅ Remediation
KB3160352 (Security Update)
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-3226
- patchhttps://www.microsoft.com/download/details.aspx?familyid=68f2762d-8f2b-45b3-bdcf-4b34fdc0c2bf
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e04e1a84-9848-4721-a312-87d317772d94
- patchhttps://www.microsoft.com/download/details.aspx?familyid=46aebb45-05d3-40be-8ace-93d2b40f2090