Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10707
HistoryJan 15, 2019 - 8:51 a.m.

Authorization Bypass

2019-01-1508:51:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.004

Percentile

73.3%

samba is vulnerable to authorization bypass attacks. The vulnerabiltiy exists as the (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the “take ownership” privilege via an LSA connection.

References