CVE-2023-4154 Information
Description
A design flaw was found in Samba’s DirSync control implementation which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes including sensitive secrets and passwords. Even in a default setup RODC DC accounts which should only replicate some passwords can gain access to all domain secrets including the vital krbtgt effectively eliminating the RODC / DC distinction. Furthermore the vulnerability fails to account for error conditions (fail open) like out-of-memory situations potentially granting access to secret attributes even under low-privileged attacker influence.
Reference
https://access.redhat.com/security/cve/CVE-2023-4154 https://bugzilla.redhat.com/show_bug.cgi?id=2241883 https://bugzilla.samba.org/show_bug.cgi?id=15424 https://www.samba.org/samba/security/CVE-2023-4154.html
Share on: