Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25717

Опубликовано: 09 нояб. 2021
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.

Меры по смягчению последствий

Setting "gensec:require_pac=true" in the smb.conf makes, due to a cache prime in winbind, the DOMAIN\user lookup succeed, provided nss_winbind is in use, 'winbind use default domain = no' (the default) and no error paths are hit.
It would be prudent to pre-create disabled users in Active Directory matching on all privileged names not held in Active Directory, eg

samba-tool user add root -H ldap://$SERVER -U$USERNAME%$PASSWORD --random-password samba-tool user add ubuntu -H ldap://$SERVER -U$USERNAME%$PASSWORD --random-password

(repeat for eg all system users under 1000 in /etc/passwd or special to any other AD-connected services, eg perhaps "admin" for a web-app)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Enterprise Linux 6samba4Out of support scope
Red Hat Enterprise Linux 9sambaNot affected
Red Hat Enterprise Linux 7sambaFixedRHSA-2021:519216.12.2021
Red Hat Enterprise Linux 8sambaFixedRHSA-2021:508213.12.2021
Red Hat Enterprise Linux 8sambaFixedRHSA-2021:508213.12.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportsambaFixedRHSA-2022:007411.01.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportsambaFixedRHSA-2022:000804.01.2022
Red Hat Gluster Storage 3.5 for RHEL 7sambaFixedRHSA-2021:484429.11.2021
Red Hat Gluster Storage 3.5 for RHEL 8sambaFixedRHSA-2021:484329.11.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2019672samba: Active Directory (AD) domain user could become root on domain members

EPSS

Процентиль: 38%
0.00161
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.

CVSS3: 8.1
nvd
больше 3 лет назад

A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.

CVSS3: 8.1
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 8.1
debian
больше 3 лет назад

A flaw was found in the way Samba maps domain users to local users. An ...

suse-cvrf
больше 3 лет назад

Security update for samba

EPSS

Процентиль: 38%
0.00161
Низкий

8.1 High

CVSS3