Lucene search

K
f5F5F5:K25499204
HistoryOct 21, 2016 - 12:00 a.m.

K25499204 : Samba vulnerability CVE-2015-8467

2016-10-2100:00:00
my.f5.com
23

AI Score

7.3

Confidence

High

EPSS

0.013

Percentile

85.8%

Security Advisory Description

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535. (CVE-2015-8467)
Impact
There is no impact; F5 products are not affected by this vulnerability.