• Skip to primary navigation
  • Skip to content
  • Skip to footer
Dovestones Software Logo

Dovestones Software

Active Directory Software and Services

  • Products
    • AD Toolset Bundle
    • AD Bulk Users
    • AD Bulk Contacts
    • AD Reporting
    • AD Bulk Export
    • AD Photos
    • AD Find and Replace
    • True Last Logon
    • Active Directory Self Service
    • AD Self Password Reset
    • AD Phonebook
    • AD Self Update
  • Solutions
    • Active Directory Self Service
    • Import users into Active Directory
    • Import Active Directory photos into SharePoint
    • Update users that already exist in Active Directory
    • Report on Active Directory Users
    • Allow users to reset their own passwords.
    • Allow employees to update their own details Active Directory
  • Testimonials
  • Downloads
  • Purchase
    • Pricing & Purchase Online
    • Resellers
    • Quote Request
    • Purchase Orders
  • Support
    • Frequently Asked Questions (FAQs)
    • Documentation
    • Support Request Form
    • Uninstall Products
    • Find my license key
    • Blog
    • Videos
  • About Us
    • Enquiry Form
    • End User License Agreement
    • Privacy Policy

Security vulnerability in AD Self Password Reset versions older than 3.0.3.0

Dec 7, 2015 Active Directory, AD Self Password Reset, Security

Security vulnerability in AD Self Password Reset v3.0.3.0 and older

We recently discovered that there is a security vulnerability in AD Self Password Reset v3.0.3.0 and older.

This vulnerability allows unauthenticated password resets of arbitrary accounts. We don’t have any examples of anyone exploiting this vulnerability.

We are currently contacting all customers who have purchased AD Self Password Reset and offering them a free upgrade to the latest version of the program. We will ensure all customers are upgraded to the latest version so no customer is left running a vulnerable version. If the contact we have for your organization does not get back to us to confirm the upgrade then we will try to contact your IT department to obtain a new contact.

We are sorry this has happened and apologize for any inconvenience this may have caused you. We have worked with a security consultancy to make sure we fixed the issue correctly and in the safest way possible for our customers and users.


How can I resolve this vulnerability?

Check the version of a file named PasswordReset.dll which can be found in the ‘bin’ folder.If the file is version 3.0.2.9 or older then you need to install the latest version of the program which can be downloaded below.

The latest version as of 7th Dec 2015 is 3.0.4.0.

https://www.dovestones.com/downloads/demos/ADSelfPasswordResetSetup.msi

The upgrade steps can be found below.

https://www.dovestones.com/upgrading-ad-self-password-reset/

If you have lost your license please contact [email protected] and we will find this for you.


More information

If you have any questions please contact [email protected].

Footer

Dovestones Software

Copyright 2005 – 2023 © Infoopia Inc.
All rights reserved.

Registered office:

Infoopia Inc.
PO Box 93383
Newmarket Ontario
L3X 1A3
Canada

Phone (voice mail):
Toll-Free 1.877.335.8909
Outside of US/Canada +1.647.478.8078

Our Newsletter

Subscribe to our newsletter to receive the latest updates. You can review our privacy policy here.