#VU32799 Permissions, Privileges, and Access Controls in Samba - CVE-2012-2111

 

#VU32799 Permissions, Privileges, and Access Controls in Samba - CVE-2012-2111

Published: April 30, 2012 / Updated: July 28, 2020


Vulnerability identifier: #VU32799
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2012-2111
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Samba
Software vendor:
Samba

Description

The vulnerability allows a remote #AU# to read and manipulate data.

The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.


Remediation

Install update from vendor's website.

External links