Back

HIGH

samba: Samba AD users with permission to write to an account can impersonate arbitrary services

Published Aug 29, 2022

Description

The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.

Affected products

Remediation

Red Hat statement

No versions of Red Hat Enterprise Linux, Red Hat Gluster Storage, or any other Red Hat Products are affected by this vulnerability.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 29, 2022
Updated Aug 2, 2024
Reserved Jan 21, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 31, 2022
ENISA EUVD
Assigner redhat
Published Aug 29, 2022
Updated Aug 2, 2024
Exploited since n/a
EUVD-2022-15499