#VU17376 Security restrictions bypass in System Security Services Daemon (SSSD) - CVE-2018-16838
Published: February 5, 2019 / Updated: May 9, 2023
System Security Services Daemon (SSSD)
SSSD
Description
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the system.
The vulnerability exists due to a flaw in sssd Group Policy Objects implementation when the GPO is not readable by SSSD due to a too strict permission settings on the server side. A remote attacker can bypass security restrictions.