Описание
Samba AD authenticated LDAP access domain takeover. Samba AD low-privilege authenticated LDAP access allows modifications to internal LDB special DNs, which permits a domain takeover.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-infra-legacy/trusty | needs-triage | |
| esm-infra-legacy/xenial | needs-triage | |
| esm-infra/bionic | needs-triage | |
| esm-infra/focal | needs-triage | |
| jammy | released | 2:4.15.13+dfsg-0ubuntu1.13 |
| noble | released | 2:4.19.5+dfsg-4ubuntu9.7 |
| resolute | released | 2:4.23.6+dfsg-1ubuntu2.2 |
| upstream | released | 4.24.5,4.23.10,4.22.11 |
Показывать по
10
Связанные уязвимости
CVSS3: 8.8
redhat
7 дней назад
A flaw was found in Samba Active Directory Domain Controller (AD DC). Improper authorization checks allow an authenticated low-privilege domain user to modify internal LDB special records through LDAP. By altering the DSDB module configuration, an attacker can bypass directory ACL enforcement on new LDAP connections and elevate privileges, potentially leading to complete domain compromise.