Samba Active Directory Domain Controller Vulnerability Affecting Kerberos Authentication
CVE-2020-25719
What is CVE-2020-25719?
A vulnerability exists in Samba when operating as an Active Directory Domain Controller that affects the implementation of Kerberos name-based authentication. The issue arises from the lack of strict enforcement of Kerberos PAC, which could lead to misinterpretation of user tickets. This confusion over user identification can result in unauthorized access and potentially a total compromise of the entire domain, thereby posing a significant security risk to environments utilizing Samba in this capacity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
samba samba 4.15.2, samba 4.14.10, samba 4.13.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
