Back to search
CVE-2014-8143
Published: Jan 17, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SSA:2015-020-01
vendor-advisory
x_refsource_SLACKWARE
openSUSE-SU-2016:1064
vendor-advisory
x_refsource_SUSE
1031615
vdb-entry
x_refsource_SECTRACK
samba-cve20148143-priv-esc(100596)
vdb-entry
x_refsource_XF
https://www.samba.org/samba/security/CVE-2014-8143
x_refsource_CONFIRM
72278
vdb-entry
x_refsource_BID
62594
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2015:0375
vendor-advisory
x_refsource_SUSE
USN-2481-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now