HomeSecuritySamba AD vulnerability allows hackers to escalate privileges

Samba AD vulnerability allows hackers to escalate privileges

A critical vulnerability has been discovered in Samba Active Directory (AD) implementations that could allow hackers to escalate privileges.

Samba AD vulnerability allows hackers to escalate privileges

CVE-2023-3961 affects Samba versions 4.13.0 and later when configured as AD domain controllers, with a CVSS v3 score of 7.5. It results from the way access controls for new objects in the AD directory service are handled.

Read also: Vulnerability in WordPress Plugin exposes websites to hackers

An authorized user can write to all attributes of a new object, even sensitive ones, due to the absence of an access (ACL) at creation. This can lead to privilege escalation, as the administrator retains significant rights on the object.

Researchers warn that exploiting this flaw could allow a malicious user to take over the entire AD infrastructure. The Samba team has released patches in versions 4.18.3, 4.17.9, and 4.16.113 to address the vulnerability. Administrators are advised to update their systems immediately, while organizations that cannot patch immediately should monitor and restrict administrative accounts.

The vulnerability affects Samba when used as an AD domain controller, but not Samba file server installations or domain member servers. Linux distributions, such as Red Hat Enterprise Linux, are not affected, as they do not ship Samba with AD domain controller capabilities.

Samba AD

See more: Dstat.cc: DDoS platform seized – Two arrested

Addressing this vulnerability should be a priority for organizations using Samba AD, due to the risk of privilege escalation. Maintaining security through timely patching and strong access controls is critical to protecting against cyberthreats. Administrators should consult the official Samba Security Advisory for details and guidance.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS