A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creation. This issue occurs because the administrator owns the object due to the lack of an Access Control List (ACL) at the time of creation and later being recognized as the 'creator owner.' The retained significant rights of the delegated administrator may not be well understood, potentially leading to unintended privilege escalation or security risks.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade samba-client-debuginfoUpgrade samba-libsUpgrade samba-dc-libsUpgrade libsmbclient-develUpgrade samba-test-libsUpgrade samba-ldb-ldap-modules-debuginfoUpgrade samba-debugsourceUpgrade samba-testUpgrade samba-commonUpgrade python3-samba-debuginfoUpgrade samba-dcerpc-debuginfoUpgrade samba-develUpgrade python3-samba-develUpgrade samba-common-tools-debuginfoUpgrade python3-samba-dcUpgrade samba-krb5-printingUpgrade samba-clientUpgrade libnetapi-develUpgrade samba-common-toolsUpgrade libnetapiUpgrade samba-libs-debuginfoUpgrade samba-winbind-krb5-locator-debuginfoUpgrade libnetapi-debuginfoUpgrade libwbclientUpgrade samba-test-debuginfoUpgrade samba-test-libs-debuginfoUpgrade samba-common-libs-debuginfoUpgrade samba-ldb-ldap-modulesUpgrade samba-winbind-krb5-locatorUpgrade python3-sambaUpgrade libsmbclient-debuginfoUpgrade samba-client-libsUpgrade samba-krb5-printing-debuginfoUpgrade sambaUpgrade samba-vfs-iouringUpgrade samba-common-libsUpgrade samba-dc-libs-debuginfoUpgrade libwbclient-debuginfoUpgrade samba-winbind-clientsUpgrade samba-debuginfoUpgrade samba-winbind-modules-debuginfoUpgrade samba-winbind-modulesUpgrade python3-samba-testUpgrade samba-client-libs-debuginfoUpgrade samba-vfs-iouring-debuginfoUpgrade samba-winbind-debuginfoUpgrade samba-winbind-clients-debuginfoUpgrade samba-dcerpcUpgrade samba-winbindUpgrade samba-usersharesUpgrade samba-pidlUpgrade libwbclient-develUpgrade python3-samba-dc-debuginfoUpgrade samba-toolsUpgrade libsmbclient | Feb 17, 2025 | Jun 14, 2022 |
| Debian | — | Upgrade samba | Jul 30, 2024 | Jul 30, 2024 |
| Suse | — | Upgrade samba-client-32bitUpgrade libsamba-policy-python3-develUpgrade samba-client-libs-32bitUpgrade libsamba-policy0-python3Upgrade samba-toolUpgrade samba-testUpgrade samba-libsUpgrade samba-clientUpgrade samba-libs-python3-32bitUpgrade samba-devel-32bitUpgrade samba-libs-32bitUpgrade libsamba-policy0-python3-32bitUpgrade samba-cephUpgrade samba-ldb-ldapUpgrade ctdbUpgrade ctdb-pcp-pmdaUpgrade samba-winbind-libsUpgrade sambaUpgrade samba-winbindUpgrade samba-libs-python3Upgrade samba-winbind-libs-32bitUpgrade samba-docUpgrade samba-python3Upgrade samba-gpupdateUpgrade samba-develUpgrade libsamba-policy-develUpgrade samba-client-libs | Aug 9, 2024 | Aug 20, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Nov 17, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 17, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub