Описание
A flaw was found in Samba Active Directory Domain Controller (AD DC). Improper authorization checks allow an authenticated low-privilege domain user to modify internal LDB special records through LDAP. By altering the DSDB module configuration, an attacker can bypass directory ACL enforcement on new LDAP connections and elevate privileges, potentially leading to complete domain compromise.
Отчет
Red Hat Product Security has rated this vulnerability as having an Important security impact for Samba deployments operating as an Active Directory Domain Controller (AD DC).
Red Hat Enterprise Linux (RHEL) context: Standard installations of Red Hat Enterprise Linux (RHEL) are not affected. RHEL packages Samba strictly to operate as a file server (smbd), print server, or Active Directory domain member (winbindd). RHEL does not ship or support the Samba Active Directory Domain Controller (AD DC) role where this internal LDB filtering flaw exists.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | samba | Not affected | ||
| Red Hat Enterprise Linux 6 | samba | Not affected | ||
| Red Hat Enterprise Linux 6 | samba4 | Not affected | ||
| Red Hat Enterprise Linux 7 | samba | Not affected | ||
| Red Hat Enterprise Linux 8 | samba | Not affected | ||
| Red Hat Enterprise Linux 9 | samba | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2502726samba: authenticated LDAP access to internal LDB special DNs permits domain takeover
8.8 High
CVSS3
8.8 High
CVSS3