CVE Vulnerabilities

CVE-2022-32744

Authentication Bypass by Spoofing

Published: Aug 25, 2022 | Modified: Sep 17, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users passwords, enabling full domain takeover.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.3.0 (including) 4.14.14 (excluding)
Samba Samba 4.15.0 (including) 4.15.9 (excluding)
Samba Samba 4.16.0 (including) 4.16.4 (excluding)

References