#VU81874 Information disclosure in Samba - CVE-2023-4154
Published: October 11, 2023
Samba
Samba
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a design error in Samba's implementation of the DirSync control, which can allow replication of critical domain passwords and secrets by Active Directory accounts authorized to do some replication, but not to replicate sensitive attributes. A remote user can obtain sensitive information from the AD DC and compromise the Active Directory.