Samba Kerberos Delegation Vulnerability in 4.x.x Versions
CVE-2019-14870

5.4MEDIUM

Key Information:

Vendor
Red Hat
Status
Vendor
CVE Published:
10 December 2019

Summary

Samba versions prior to 4.9.17, 4.10.11, and 4.11.3 exhibit a flaw in the S4U Kerberos delegation model, whereby certain clients can be bypassed from constrained delegation protections. Specifically, even if a client is flagged as non-delegatable in Active Directory through the 'delegation_not_allowed' attribute, Samba inadvertently allows the impersonation of these clients with forwardable tickets. This oversight could lead to unauthorized access to services by compromised accounts, making it crucial for administrators to update to the patched versions promptly to maintain network integrity.

Affected Version(s)

samba all versions 4.11.x before 4.11.3

samba all versions 4.10.x before 4.10.11

samba all versions 4.x.x before 4.9.17

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.