#VU65825 Permissions, Privileges, and Access Controls in Samba - CVE-2022-32744

 

#VU65825 Permissions, Privileges, and Access Controls in Samba - CVE-2022-32744

Published: July 27, 2022 / Updated: April 21, 2023


Vulnerability identifier: #VU65825
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-32744
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Samba
Software vendor:
Samba

Description

The vulnerability allows a remote user to force password change requests.

The vulnerability exists due to tickets received by the kpasswd service were decrypted without specifying that only that service's own keys should be tried. A remote user can force the server to accept tickets encrypted with any key and initiate password change requests for any Samba AD user.


Remediation

Install updates from vendor's website.

External links