Описание
Netlogon RPC Elevation of Privilege Vulnerability
A flaw was found in samba. The Netlogon RPC implementations may use the rc4-hmac encryption algorithm, which is considered weak and should be avoided even if the client supports more modern encryption types. This issue could allow an attacker who knows the plain text content communicated between the samba client and server to craft data with the same MD5 calculation and replace it without being detected.
Меры по смягчению последствий
Users can disable MD5-based NetLogon by adding the following snippet to their smb.conf
reject md5 clients = yes
in case there's still need to allow SMB to authenticate to MD5-based NetLogon servers, it's possible to explicitly enable it per-server based:
server reject md5 schannel:<SERVERNAME>$ = no
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | samba | Out of support scope | ||
Red Hat Storage 3 | samba | Not affected | ||
Red Hat Enterprise Linux 7 | samba | Fixed | RHSA-2023:1090 | 07.03.2023 |
Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2023:0838 | 21.02.2023 |
Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2023:0838 | 21.02.2023 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | samba | Fixed | RHSA-2023:0639 | 07.02.2023 |
Red Hat Enterprise Linux 8.2 Advanced Update Support | samba | Fixed | RHSA-2023:0638 | 07.02.2023 |
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | samba | Fixed | RHSA-2023:0638 | 07.02.2023 |
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | samba | Fixed | RHSA-2023:0638 | 07.02.2023 |
Red Hat Enterprise Linux 8.4 Extended Update Support | samba | Fixed | RHSA-2023:0637 | 07.02.2023 |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-328
https://bugzilla.redhat.com/show_bug.cgi?id=2154362samba: RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided
EPSS
Процентиль: 61%
0.00419
Низкий
8.1 High
CVSS3
EPSS
Процентиль: 61%
0.00419
Низкий
8.1 High
CVSS3