#VU78573 Security features bypass in Samba - CVE-2023-3347
Published: July 24, 2023
Samba
Samba
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to SMB2 packet signing feature is not enforced if the server is configured with the "server signing = required" option or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. A remote attacker can intercept and manipulate data.