A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
2022-08-25T18:15:10.497
2024-11-21T07:06:52.597
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | samba | samba | < 4.14.14 | Yes |
Application | samba | samba | < 4.15.9 | Yes |
Application | samba | samba | < 4.16.4 | Yes |