A flaw was found in the way Samba, as an Active Directory...
High severity
Unreviewed
Published
Feb 19, 2022
to the GitHub Advisory Database
•
Updated Sep 17, 2023
Description
Published by the National Vulnerability Database
Feb 18, 2022
Published to the GitHub Advisory Database
Feb 19, 2022
Last updated
Sep 17, 2023
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.
References