Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-1057
HistoryMar 13, 2018 - 4:29 p.m.

Code injection

2018-03-1316:29:00
PRIOn knowledge base
www.prio-n.com
19

8.3 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users’ passwords, including administrative users and privileged service accounts (eg Domain Controllers).