samba: Unconditional privilege delegation to Kerberos servers in trusted realms
Published Oct 31, 2018
6.5
MEDIUMCVSS 3.1
EPSS 9.20%
Description
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
Affected products
- Vendor n/a Product Samba Defaultn/a
- Version 4.3.13StatusaffectedConstraints-
- Version 4.4.8StatusaffectedConstraints-
- Version 4.5.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Samba | n/a |
|
Configuration 1
Configuration 2
- 3.0
- 6.0
- 7.0
- 6.0
- 7.0
- 7.4
- 7.6
- 7.3
- 7.4
- 7.5
- 7.6
- 7.3
- 7.6
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 6
samba-0:3.6.23-41.el6
Fixed · RHSA-2017:0662
Red Hat Enterprise Linux 6
samba4-0:4.2.10-9.el6
Fixed · RHSA-2017:0744
Red Hat Enterprise Linux 7
samba-0:4.4.4-13.el7_3
Fixed · RHSA-2017:1265
Red Hat Gluster Storage 3.2 for RHEL 6
samba-0:4.4.6-4.el6rhs
Fixed · RHSA-2017:0494
Red Hat Gluster Storage 3.2 for RHEL 7
samba-0:4.4.6-4.el7rhgs
Fixed · RHSA-2017:0495
Red Hat Enterprise Linux 5
samba
Will not fix
Red Hat Enterprise Linux 5
samba3x
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | samba-0:3.6.23-41.el6 | Fixed | RHSA-2017:0662 |
| Red Hat Enterprise Linux 6 | samba4-0:4.2.10-9.el6 | Fixed | RHSA-2017:0744 |
| Red Hat Enterprise Linux 7 | samba-0:4.4.4-13.el7_3 | Fixed | RHSA-2017:1265 |
| Red Hat Gluster Storage 3.2 for RHEL 6 | samba-0:4.4.6-4.el6rhs | Fixed | RHSA-2017:0494 |
| Red Hat Gluster Storage 3.2 for RHEL 7 | samba-0:4.4.6-4.el7rhgs | Fixed | RHSA-2017:0495 |
| Red Hat Enterprise Linux 5 | samba | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | samba3x | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
The following mitigation is suggested by upstream. The samba-tool command and the AD DC mode honours the undocumented "gensec_gssapi:delegation=no" option in the [global] section of the smb.conf file. Controlling Kerberos forwarding =============================== In the Active Directory world it's possible for administrators to limit the delegation. User and computer objects can both act as Kerberos users and also as Kerberos services. Both types of objects have an attribute called 'userAccountControl' which is a bitmask that controls the behavior of the account. The following three values have impact on possible delegation: 0x00100000: UF_NOT_DELEGATED: The UF_NOT_DELEGATED can be used to disable the ability to get forwardable TGT for the account. It means the KDC will respond with an error if the client asks for the forwardable ticket. The client typically gives up and removes the GSS_C_DELEG_FLAG flag and continues without passing delegated credentials. Administrators can use this to disable possible delegation for the most privileged accounts (e.g. administrator accounts). 0x00080000: UF_TRUSTED_FOR_DELEGATION If the UF_TRUSTED_FOR_DELEGATION is set on an account a KDC will include the OK_AS_DELEGATE flag in a granted service ticket. If the client application uses just GSS_C_DELEG_POLICY_FLAG (instead of GSS_C_DELEG_FLAG) gssapi/Kerberos libraries typically only include delegated credentials when the service ticket includes the OK_AS_DELEGATE flag. Administrators can use this to control which services will get delegated credentials, for example if the service runs in a trusted environment and actually requires the presence of delegated credentials. 0x01000000: UF_TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION The UF_TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION is not really relevant for this CVE and just listed here for completeness. This flag is relevant for the S4U2Proxy feature, where a service can ask the KDC for a proxied service ticket which can impersonate users to other services.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
AV:A/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.20% (0.09199) | 95.19th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.27% (0.09273) | 94.70th | v5 (v2026.06.15) |
| May 29, 2026 | 8.66% (0.08663) | 92.58th | v4 (v2025.03.14) |
| Jan 14, 2026 | 10.87% (0.10867) | 93.15th | v4 (v2025.03.14) |
| Nov 30, 2025 | 9.84% (0.09844) | 92.69th | v4 (v2025.03.14) |
| Oct 19, 2025 | 15.62% (0.15618) | 94.38th | v4 (v2025.03.14) |
| Mar 30, 2025 | 12.99% (0.12986) | 93.45th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.91% (0.04913) | 82.29th | v4 (v2025.03.14) |
| Mar 17, 2025 | 13.91% (0.13911) | 93.78th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.48% (0.00477) | 76.56th | v3 (v2023.03.01) |
| May 2, 2024 | 0.53% (0.00533) | 76.89th | v3 (v2023.03.01) |
| Apr 10, 2024 | 0.65% (0.00651) | 79.10th | v3 (v2023.03.01) |
| Oct 25, 2023 | 0.65% (0.00651) | 77.08th | v3 (v2023.03.01) |
| Sep 6, 2023 | 0.57% (0.00567) | 75.02th | v3 (v2023.03.01) |
| Mar 14, 2023 | 0.46% (0.00463) | 71.54th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.43% (0.00434) | 70.61th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.54% (0.01537) | 51.33th | v2 (v2022.01.01) |
References (13)
- http://rhn.redhat.com/errata/RHSA-2017-0494.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0495.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0662.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0744.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/bid/94988 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037494 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1265 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-2125 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1403114 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2125 x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-2125
- https://www.cve.org/CVERecord?id=CVE-2016-2125
- https://www.samba.org/samba/security/CVE-2016-2125.html x_refsource_CONFIRMMitigationPatchVendor Advisory
Change history (0)
No recorded changes yet.