CVE Database
/

CVE-2014-8143

Back to search

CVE-2014-8143

Published: Jan 17, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.

VendorProductVersions

n/a

n/a

affected
n/a

References

SSA:2015-020-01
vendor-advisory
x_refsource_SLACKWARE
openSUSE-SU-2016:1064
vendor-advisory
x_refsource_SUSE
1031615
vdb-entry
x_refsource_SECTRACK
samba-cve20148143-priv-esc(100596)
vdb-entry
x_refsource_XF
72278
vdb-entry
x_refsource_BID
62594
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2015:0375
vendor-advisory
x_refsource_SUSE
USN-2481-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now