Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-45141


Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).


Published

2023-03-06T23:15:11.157

Last Modified

2025-03-06T21:15:12.980

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-328
  • Type: Secondary
    CWE-326
  • Type: Secondary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application samba samba < 4.15.13 Yes
Application samba samba < 4.16.8 Yes

References