CVE-2012-2111
published 2012-04-30CVE-2012-2111: The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.80%
91.0th percentile
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_workspace | — | — |
| debian | samba | < samba 2:3.6.5-1 (bookworm) | samba 2:3.6.5-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2022-21825: An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker
vendor_citrix·2022-02-09·CVSS 7.8
CVE-2022-21825 [HIGH] CWE-284 CVE-2022-21825: An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker
CVE-2022-21825: An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
Ubuntu
Samba vulnerability
vendor_ubuntu·2012-05-01
CVE-2012-2111 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could allow a user to gain administrative privileges to the Samba server.
Ivano Cristofolini discovered that Samba incorrectly handled some Local
Security Authority (LSA) remote procedure calls (RPC). A remote, authenticated
attacker could exploit this to grant administrative privileges to arbitrary
users. The administrative privileges could be used to bypass permission checks
performed by the Samba server.
Instructions: After a standard system update you may need to review the privileges of Samba
user accounts.
Red Hat
samba: Incorrect permission checks when granting/removing privileges
vendor_redhat·2012-04-30·CVSS 6.5
CVE-2012-2111 [MEDIUM] samba: Incorrect permission checks when granting/removing privileges
samba: Incorrect permission checks when granting/removing privileges
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Package: samba (Red Hat Enterprise Linux 4) - Not affected
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-2111: samba - The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAcco...
vendor_debian·2012·CVSS 6.5
CVE-2012-2111 [MEDIUM] CVE-2012-2111: samba - The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAcco...
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Scope: local
bookworm: resolved (fixed in 2:3.6.5-1)
bullseye: resolved (fixed in 2:3.6.5-1)
forky: resolved (fixed in 2:3.6.5-1)
sid: resolved (fixed in 2:3.6.5-1)
trixie: resolved (fixed in 2:3.6.5-1)
Citrix
Citrix Workspace App for Linux Security Update
vendor_citrix·CVSS 7.8
CVE-2022-21825 [HIGH] CWE-284 Citrix Workspace App for Linux Security Update
Citrix Workspace App for Linux Security Update
Vulnerability Type Pre-conditions CVE-2022-21825 Local privilege Escalation CWE-284: Improper Access Control Local user access to a system where Citrix Workspace App for Linux has been installed with App Protection. This vulnerability only affects Citrix Workspace app for Linux 2012 - 2111 and only exists if App Protection was installed as part of Citrix Workspace app for Linux. This vulnerability does not exist if App Protection is not installed. Citrix Workspace app for other platforms is not affected by this issue. Instructions This issue has been addressed in the following versions of Citrix Workspace app for Linux: Citrix Workspace App for Linux 2112 and later versions Citrix strongly recommends that affected customers upgrade to a
CVE
GHSA
GHSA-7948-mr73-p8vq: The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3
ghsa_unreviewed·2022-05-14
CVE-2012-2111 [MEDIUM] GHSA-7948-mr73-p8vq: The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
OSV
CVE-2012-2111: The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3
osv·2012-04-30·CVSS 6.5
CVE-2012-2111 [MEDIUM] CVE-2012-2111: The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2111 samba: Incorrect permission checks when granting/removing privileges [fedora-all]
bugzilla·2012-04-30·CVSS 6.5
CVE-2012-2111 [MEDIUM] CVE-2012-2111 samba: Incorrect permission checks when granting/removing privileges [fedora-all]
CVE-2012-2111 samba: Incorrect permission checks when granting/removing privileges [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates
Bugzilla
CVE-2012-2111 samba: Incorrect permission checks when granting/removing privileges
bugzilla·2012-04-17·CVSS 6.5
CVE-2012-2111 [MEDIUM] CVE-2012-2111 samba: Incorrect permission checks when granting/removing privileges
CVE-2012-2111 samba: Incorrect permission checks when granting/removing privileges
A vulnerability was found in Samba 3.4.x through to and including 3.6.4 that could allow arbitrary users to modify privileges on a Samba file server. This is due to security checks being incorrectly applied to the Local Security Authority (LSA) remote procedure calls (RPC): CreateAccount, OpenAccount, AddAccountRights, and RemoveAccountRights.
This could allow any authenticated user to modify the privileges database. As a result, this could allow an attacker to grant themselves the "take ownership" privilege, which would allow the attacker to take ownership of files or directories that they do not own.
To work-around this flaw, set the "enable privileges = no" parameter in the "[global]" section of smb.co
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079662.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079670.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079677.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00003.htmlhttp://marc.info/?l=bugtraq&m=134323086902585&w=2http://osvdb.org/81648http://rhn.redhat.com/errata/RHSA-2012-0533.htmlhttp://secunia.com/advisories/48976http://secunia.com/advisories/48984http://secunia.com/advisories/48996http://secunia.com/advisories/48999http://secunia.com/advisories/49017http://secunia.com/advisories/49030http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578http://www.debian.org/security/2012/dsa-2463http://www.mandriva.com/security/advisories?name=MDVSA-2012:067http://www.samba.org/samba/security/CVE-2012-2111http://www.securitytracker.com/id?1026988http://www.ubuntu.com/usn/USN-1434-1http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079662.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079670.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079677.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00003.htmlhttp://marc.info/?l=bugtraq&m=134323086902585&w=2http://osvdb.org/81648http://rhn.redhat.com/errata/RHSA-2012-0533.htmlhttp://secunia.com/advisories/48976http://secunia.com/advisories/48984http://secunia.com/advisories/48996http://secunia.com/advisories/48999http://secunia.com/advisories/49017http://secunia.com/advisories/49030http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578http://www.debian.org/security/2012/dsa-2463http://www.mandriva.com/security/advisories?name=MDVSA-2012:067http://www.samba.org/samba/security/CVE-2012-2111http://www.securitytracker.com/id?1026988http://www.ubuntu.com/usn/USN-1434-1
2012-04-30
Published