#VU65825 Permissions, Privileges, and Access Controls in Samba - CVE-2022-32744
Published: July 27, 2022 / Updated: April 21, 2023
Samba
Samba
Description
The vulnerability allows a remote user to force password change requests.
The vulnerability exists due to tickets received by the kpasswd service were decrypted without specifying that only that service's own keys should be tried. A remote user can force the server to accept tickets encrypted with any key and initiate password change requests for any Samba AD user.