CVE-2023-4154
Summary
| CVE | CVE-2023-4154 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-07 20:15:00 UTC |
| Updated | 2023-11-15 15:40:00 UTC |
| Description | A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which should only replicate some passwords, can gain access to all domain secrets, including the vital krbtgt, effectively eliminating the RODC / DC distinction. Furthermore, the vulnerability fails to account for error conditions (fail open), like out-of-memory situations, potentially granting access to secret attributes, even under low-privileged attacker influence. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2241883 – (CVE-2023-4154) CVE-2023-4154 samba: AD DC password exposure to privileged users and RODCs | bugzilla.redhat.com | ||
| 15424 – (CVE-2023-4154) CVE-2023-4154 [SECURITY] dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES" | bugzilla.samba.org | ||
| cve-details | access.redhat.com | ||
| Samba - Security Announcement Archive | www.samba.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199820 Ubuntu Security Notification for Samba Vulnerabilities (USN-6425-1)
- 199907 Ubuntu Security Notification for Samba Vulnerabilities (USN-6425-3)
- 284612 Fedora Security Update for samba (FEDORA-2023-7eb8cbf1a5)
- 284682 Fedora Security Update for samba (FEDORA-2023-fff0c857d6)
- 285191 Fedora Security Update for samba (FEDORA-2023-8c9251e479)
- 503395 Alpine Linux Security Update for samba
- 505937 Alpine Linux Security Update for samba
- 6000310 Debian Security Update for samba (DSA 5525-1)
- 673574 EulerOS Security Update for samba (EulerOS-SA-2023-3286)
- 673680 EulerOS Security Update for samba (EulerOS-SA-2023-3258)
- 710873 Gentoo Linux Samba Multiple Vulnerabilities (GLSA 202402-28)
- 755069 SUSE Enterprise Linux Security Update for samba (SUSE-SU-2023:4046-1)
- 755081 SUSE Enterprise Linux Security Update for samba (SUSE-SU-2023:4059-1)
- 755106 SUSE Enterprise Linux Security Update for samba (SUSE-SU-2023:4096-1)