Severity
9.8CRITICALNVD
OSV6.5OSV5.9
EPSS
0.7%
top 28.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateJun 30

Description

Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

NVDsamba/samba4.16.04.16.8+1
debiandebian/samba< samba 2:4.16.0+dfsg-2 (bookworm)
Debiansamba/samba< 2:4.16.0+dfsg-2+2
Ubuntusamba/samba< 2:4.15.13+dfsg-0ubuntu0.20.04.1+9
CVEListV5samba/sambaFixed in samba 4.15.13, samba 4.16.8, samba 4.15.13

🔴Vulnerability Details

7
OSV
samba regression2025-06-30
OSV
samba vulnerabilities2025-06-19
OSV
samba vulnerabilities2023-03-08
GHSA
GHSA-g5hg-3x62-v52f: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that r2023-03-07
OSV
CVE-2022-45141: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that r2023-03-06

📋Vendor Advisories

8
Ubuntu
Samba regression2025-06-30
Ubuntu
Samba vulnerabilities2025-06-19
Microsoft
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak Vulnerable Samba Active Directory 2023-03-14
Ubuntu
Samba vulnerabilities2023-03-08
Ubuntu
Samba regression2023-01-26
CVE-2022-45141 — Use of Weak Hash in Samba | cvebase