Lucene search

K
f5F5F5:K93951507
HistoryApr 06, 2021 - 12:00 a.m.

K93951507 : Multiple Samba vulnerabilities

2021-04-0600:00:00
my.f5.com
41

7.9 High

AI Score

Confidence

Low

0.467 Medium

EPSS

Percentile

97.5%

Security Advisory Description

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka ‘Netlogon Elevation of Privilege Vulnerability’.

A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

A null pointer dereference flaw was found in samba’s Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.

Impact

There is no impact; F5 products are not affected by this vulnerability.