Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1057
HistoryMar 13, 2018 - 10:19 a.m.

CVE-2018-1057

2018-03-1310:19:11
redhat.com
access.redhat.com
13

0.011 Low

EPSS

Percentile

84.2%

A flaw was found in the way Samba AD DC validated user permissions. An authenticated attacker could use this flaw to change any other users passwords, including administrative users.

Mitigation

Revoke the change passwords right for everyone from all user objects (including computers) in the directory. Note that this will prevent users from being able to change their own expired passwords, so the maximum password age should be set to a value that prevents user passwords from expiring while the workaround is in place. For more information please refer to: <https://bugzilla.redhat.com/show_bug.cgi?id=1553553#c3&gt;