Samba Active Directory Domain Controller Vulnerability Affecting Kerberos Authentication
CVE-2020-25719

7.2HIGH

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
18 February 2022

What is CVE-2020-25719?

A vulnerability exists in Samba when operating as an Active Directory Domain Controller that affects the implementation of Kerberos name-based authentication. The issue arises from the lack of strict enforcement of Kerberos PAC, which could lead to misinterpretation of user tickets. This confusion over user identification can result in unauthorized access and potentially a total compromise of the entire domain, thereby posing a significant security risk to environments utilizing Samba in this capacity.

Affected Version(s)

samba samba 4.15.2, samba 4.14.10, samba 4.13.14

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.