Account Misconfiguration in Samba Affecting Key Distribution Center Services
CVE-2022-2031
What is CVE-2022-2031?
A security flaw in Samba occurs when the Key Distribution Center (KDC) and the kpasswd service operate under a shared account and set of keys. This misconfiguration allows a malicious user, specifically one who has been prompted to change their password, to manipulate the system and leverage the deceptive capability to decrypt tickets issued for other services. As a result, the attacker could gain unauthorized access to sensitive resources and perform actions under the guise of legitimate credentials.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
samba Versions prior to samba 4.16.4, samba 4.15.9, samba 4.14.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
