logo

W32.Coozie: Discovering Oracle CVE-2018-3253

ID: daf85a5e-616a-58ba-991f-2cd4d02497be

STIX ID: report--daf85a5e-616a-58ba-991f-2cd4d02497be

Feed Name: TrustedSec blog

Threat Score
80/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This post describes discovery and exploitation of an Oracle configuration/implementation flaw (CVE-2018-3253) where an Oracle password filter (oidpwdcn.dll) writes unsalted SHA1 password hashes into the Active Directory attribute orclCommonAttribute and those values are readable by Authenticated Users. The author retrieved the attribute values via LDAPS, cracked thousands of passwords, achieved Domain Admin access during a red-team engagement, reported the issue to Oracle, and Oracle released a patch in October 2018.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.