CVE Database
/

CVE-2015-8467

Back to search

CVE-2015-8467

Published: Dec 29, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

VendorProductVersions

n/a

n/a

affected
n/a

References

79735
vdb-entry
x_refsource_BID
openSUSE-SU-2016:1064
vendor-advisory
x_refsource_SUSE
USN-2855-2
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2015:2304
vendor-advisory
x_refsource_SUSE
SUSE-SU-2015:2305
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2015:2354
vendor-advisory
x_refsource_SUSE
1034493
vdb-entry
x_refsource_SECTRACK
DSA-3433
vendor-advisory
x_refsource_DEBIAN
GLSA-201612-47
vendor-advisory
x_refsource_GENTOO
USN-2855-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2015:2356
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now