#VU83535 Improper access control in Samba - CVE-2018-14628
Published: November 28, 2023
Samba
Samba
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper access restrictions when Samba is an Active Directory Domain Controller. When a domain was provisioned with an unpatched Samba version, the ntSecurityDescriptor is simply inherited from Domain/Partition-HEAD-Object instead of being very strict (as on a Windows provisioned domain). This means also non privileged users can use the LDAP_SERVER_SHOW_DELETED_OID control in order to view, the names and preserved attributes of deleted objects.