A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
References
Link | Resource |
---|---|
https://www.samba.org/samba/security/CVE-2022-32744.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-08-25 11:15
Updated : 2022-08-29 11:09
NVD link : CVE-2022-32744
Mitre link : CVE-2022-32744
JSON object : View
CWE
CWE-290
Authentication Bypass by Spoofing
Products Affected
samba
- samba