Back to search
CVE-2020-25719
Published: Feb 18, 2022
Modified: Aug 4, 2024
PUBLISHED
Description
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.
| Vendor | Product | Versions |
|---|---|---|
n/a | samba | affected samba 4.15.2, samba 4.14.10, samba 4.13.14 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now