CVE-2022-0336
published 2022-08-29CVE-2022-0336: The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database…
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.30%
67.3th percentile
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.16.0+dfsg-2 (bookworm) | samba 2:4.16.0+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1~deb11u3 | 2:4.13.13+dfsg-1~deb11u3 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.17~dfsg-0ubuntu0.21.04.1 | 2:4.13.17~dfsg-0ubuntu0.21.04.1 |
| samba | samba | >= 4.0.0 < 4.13.17 | 4.13.17 |
| samba | samba | >= 4.14.0 < 4.14.12 | 4.14.12 |
| samba | samba | >= 4.15.0 < 4.15.4 | 4.15.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu2.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypas
vendor_msrc·2022-08-09·CVSS 8.8
CVE-2022-0336 [HIGH] CWE-276 The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypas
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally an attacker who can intercept traffic can impersonate existing services resulting in a loss of confidentiality and integrity.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One o
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2022-02-01·CVSS 2.5
CVE-2022-0336 [LOW] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Michael Hanselmann discovered that Samba incorrectly created directories.
In certain configurations, a remote attacker could possibly create a
directory on the server outside of the shared directory. (CVE-2021-43566)
Kees van Vloten discovered that Samba incorrectly handled certain aliased
SPN checks. A remote attacker could possibly use this issue to impersonate
services. (CVE-2022-0336)
Instructions: This update uses a new upstream release, whic
Red Hat
samba: Samba AD users with permission to write to an account can impersonate arbitrary services
vendor_redhat·2022-01-31·CVSS 8.8
CVE-2022-0336 [HIGH] CWE-276 samba: Samba AD users with permission to write to an account can impersonate arbitrary services
samba: Samba AD users with permission to write to an account can impersonate arbitrary services
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.
A logic flaw in the Samba Active Directory Domain Co
Debian
CVE-2022-0336: samba - The Samba AD DC includes checks when adding service principals names (SPNs) to a...
vendor_debian·2022·CVSS 8.8
CVE-2022-0336 [HIGH] CVE-2022-0336: samba - The Samba AD DC includes checks when adding service principals names (SPNs) to a...
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.
Scope: local
bookworm: resolved (fixed in 2:4.16.0+dfsg-2)
bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u3)
forky: resolved (fixed in 2:4.16.0+d
OSV
CVE-2022-0336: The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the d
osv·2022-08-29·CVSS 8.8
CVE-2022-0336 [HIGH] CVE-2022-0336: The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the d
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.
GHSA
GHSA-rg44-hwh5-vcpq: The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the d
ghsa_unreviewed·2022-08-29
CVE-2022-0336 [HIGH] CWE-276 GHSA-rg44-hwh5-vcpq: The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the d
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.
OSV
samba vulnerabilities
osv·2022-02-01·CVSS 2.5
CVE-2021-44142 [LOW] samba vulnerabilities
samba vulnerabilities
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Michael Hanselmann discovered that Samba incorrectly created directories.
In certain configurations, a remote attacker could possibly create a
directory on the server outside of the shared directory. (CVE-2021-43566)
Kees van Vloten discovered that Samba incorrectly handled certain aliased
SPN checks. A remote attacker could possibly use this issue to impersonate
services. (CVE-2022-0336)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-0336https://bugzilla.redhat.com/show_bug.cgi?id=2046134https://bugzilla.samba.org/show_bug.cgi?id=14950https://github.com/samba-team/samba/commit/1a5dc817c0c9379bbaab14c676681b42b0039a3chttps://github.com/samba-team/samba/commit/c58ede44f382bd0125f761f0479c8d48156be400https://security.gentoo.org/glsa/202309-06https://www.samba.org/samba/security/CVE-2022-0336.htmlhttps://access.redhat.com/security/cve/CVE-2022-0336https://bugzilla.redhat.com/show_bug.cgi?id=2046134https://bugzilla.samba.org/show_bug.cgi?id=14950https://github.com/samba-team/samba/commit/1a5dc817c0c9379bbaab14c676681b42b0039a3chttps://github.com/samba-team/samba/commit/c58ede44f382bd0125f761f0479c8d48156be400https://security.gentoo.org/glsa/202309-06https://www.samba.org/samba/security/CVE-2022-0336.html
2022-08-29
Published