CVE-2020-25721
published 2022-03-16CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable…
PriorityP348high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.03%
79.0th percentile
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.13.14+dfsg-1 (bookworm) | samba 2:4.13.14+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1~deb11u2 | 2:4.13.13+dfsg-1~deb11u2 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-1 | 2:4.13.14+dfsg-1 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-1 | 2:4.13.14+dfsg-1 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-1 | 2:4.13.14+dfsg-1 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-0ubuntu0.20.04.4 | 2:4.13.14+dfsg-0ubuntu0.20.04.4 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-0ubuntu0.20.04.3 | 2:4.13.14+dfsg-0ubuntu0.20.04.3 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-0ubuntu0.20.04.1 | 2:4.13.14+dfsg-0ubuntu0.20.04.1 |
| samba | samba | >= 4.13.0 < 4.13.14 | 4.13.14 |
| samba | samba | >= 4.14.0 < 4.14.10 | 4.14.10 |
| samba | samba | >= 4.15.0 < 4.15.2 | 4.15.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wcq8-frw5-cgvr: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid)
ghsa_unreviewed·2022-03-17
CVE-2020-25721 [HIGH] CWE-20 GHSA-wcq8-frw5-cgvr: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid)
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
OSV
CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid)
osv·2022-03-16·CVSS 8.8
CVE-2020-25721 [HIGH] CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid)
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
OSV
samba regression
osv·2021-12-13·CVSS 5.9
[MEDIUM] samba regression
samba regression
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced a regression in Kerberos authentication in certain environments.
Please see the following upstream bug for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14922
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not correctly sandbox
OSV
samba regressions
osv·2021-12-06·CVSS 5.9
[MEDIUM] samba regressions
samba regressions
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced regressions in name mapping and backups.
Please see the following upstream bugs for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14901
https://bugzilla.samba.org/show_bug.cgi?id=14918
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba
OSV
samba vulnerabilities
osv·2021-11-11·CVSS 5.9
CVE-2016-2124 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not correctly sandbox Kerberos
tickets issues by an RODC. An RODC could print administrator tickets,
contrary to expectations. (CVE-2020-25718)
Andrew Bartlett discovered that Samba incorrectly handled Kerberos tickets.
Delegated administrators could possibly use this issue to impersonate
accounts, leading to total domain compromise.
Ubuntu
Samba regression
vendor_ubuntu·2021-12-13·CVSS 5.9
[MEDIUM] Samba regression
Title: Samba regression
Summary: USN-5142-1 introduced a regression in Samba.
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced a regression in Kerberos authentication in certain environments.
Please see the following upstream bug for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14922
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
An
Ubuntu
Samba regressions
vendor_ubuntu·2021-12-06·CVSS 5.9
[MEDIUM] Samba regressions
Title: Samba regressions
Summary: USN-5142-1 introduced regressions in Samba.
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced regressions in name mapping and backups.
Please see the following upstream bugs for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14901
https://bugzilla.samba.org/show_bug.cgi?id=14918
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain mem
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2021-11-11·CVSS 5.9
CVE-2020-25721 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not correctly sandbox Kerberos
tickets issues by an RODC. An RODC could print administrator tickets,
contrary to expectations. (CVE-2020-25718)
Andrew Bartlett discovered that Samba incorrectly handled Kerberos tickets.
Delegated administrators could possibly use this issu
Red Hat
samba: Kerberos acceptors need easy access to stableAD identifiers (eg objectSid)
vendor_redhat·2021-11-09·CVSS 8.8
CVE-2020-25721 [HIGH] CWE-20 samba: Kerberos acceptors need easy access to stableAD identifiers (eg objectSid)
samba: Kerberos acceptors need easy access to stableAD identifiers (eg objectSid)
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Package: samba (Red Hat Enterprise Linux 8) - Not affected
Package: samba (Red Hat Enterprise Linux 9) - Not affected
Package: samba (Red Hat Storage 3) - Not affected
Debian
CVE-2020-25721: samba - Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Sam...
vendor_debian·2020·CVSS 8.8
CVE-2020-25721 [HIGH] CVE-2020-25721: samba - Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Sam...
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
Scope: local
bookworm: resolved (fixed in 2:4.13.14+dfsg-1)
bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u2)
forky: resolved (fixed in 2:4.13.14+dfsg-1)
sid: resolved (fixed in 2:4.13.14+dfsg-1)
trixie: resolved (fixed in 2:4.13.14+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2021728https://bugzilla.samba.org/show_bug.cgi?id=14725https://security.gentoo.org/glsa/202309-06https://www.samba.org/samba/security/CVE-2020-25721.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2021728https://bugzilla.samba.org/show_bug.cgi?id=14725https://security.gentoo.org/glsa/202309-06https://www.samba.org/samba/security/CVE-2020-25721.html
2022-03-16
Published