Access and Conformance Checking Flaws in Samba Active Directory Domain Controller
CVE-2020-25722

8.8HIGH

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
18 February 2022

What is CVE-2020-25722?

Multiple vulnerabilities in Samba's Active Directory Domain Controller (AD DC) have been identified relating to improper access and conformance checking of stored data. An attacker exploiting these flaws could potentially achieve total compromise of the domain, undermining security protocols and granting unauthorized access to sensitive resources. This risk necessitates immediate attention to perform adequate assessments and apply necessary patches to safeguard against potential exploitations.

Affected Version(s)

samba samba 4.15.2, samba 4.14.10, samba 4.13.14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.