Samba: ad dc password exposure to privileged users and rodcs
Published Nov 7, 2023
7.5
HIGHCVSS 3.1
EPSS 1.15%
Description
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which should only replicate some passwords, can gain access to all domain secrets, including the vital krbtgt, effectively eliminating the RODC / DC distinction. Furthermore, the vulnerability fails to account for error conditions (fail open), like out-of-memory situations, potentially granting access to secret attributes, even under low-privileged attacker influence.
Affected products
No data.
Red Hat Enterprise Linux 6
samba
Not affected
Red Hat Enterprise Linux 6
samba4
Not affected
Red Hat Enterprise Linux 7
samba
Not affected
Red Hat Enterprise Linux 8
samba
Not affected
Red Hat Enterprise Linux 9
samba
Not affected
Red Hat Storage 3
samba
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 8 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 9 | samba | Not affected | n/a |
| Red Hat Storage 3 | samba | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Samba package as shipped with Red Hat Enterprise Linux 6, 7, 8 and 9 and Red Hat Gluster Storage is not affected by this issue as Red Hat doesn't provide the AD Domain Controller capability with it.
References (7)
- https://access.redhat.com/security/cve/CVE-2023-4154 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2241883 issue-trackingx_refsource_REDHATIssue Tracking
- https://bugzilla.samba.org/show_bug.cgi?id=15424 Issue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2023-4154
- https://security.netapp.com/advisory/ntap-20231124-0002/
- https://www.cve.org/CVERecord?id=CVE-2023-4154
- https://www.samba.org/samba/security/CVE-2023-4154.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-4154 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2241883 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://bugzilla.samba.org/show_bug.cgi?id=15424 | Issue TrackingPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-4154 | ||
| https://security.netapp.com/advisory/ntap-20231124-0002/ | ||
| https://www.cve.org/CVERecord?id=CVE-2023-4154 | ||
| https://www.samba.org/samba/security/CVE-2023-4154.html | Vendor Advisory |
Change history (0)
No recorded changes yet.