Lucene search

K
freebsdFreeBSDD4F45676-9D33-11E4-8275-000C292E4FD8
HistoryJan 15, 2015 - 12:00 a.m.

samba -- Elevation of privilege to Active Directory Domain Controller

2015-01-1500:00:00
vuxml.freebsd.org
20

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

EPSS

0.004

Percentile

73.8%

Samba team reports:

In Samba’s AD DC we neglected to ensure that
attempted modifications of the userAccountControl attribute
did not allow the UF_SERVER_TRUST_ACCOUNT bit to be set.

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

EPSS

0.004

Percentile

73.8%