CVE-2022-45141
published 2023-03-06CVE-2022-45141: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
36.7th percentile
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.16.0+dfsg-2 (bookworm) | samba 2:4.16.0+dfsg-2 (bookworm) |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| samba | samba | < 4.15.13 | 4.15.13 |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.1 | 2:4.15.13+dfsg-0ubuntu0.20.04.1 |
| samba | samba | >= 0 < 2:4.13.17~dfsg-0ubuntu1.20.04.5 | 2:4.13.17~dfsg-0ubuntu1.20.04.5 |
| samba | samba | >= 0 < 2:4.13.17~dfsg-0ubuntu1.20.04.4 | 2:4.13.17~dfsg-0ubuntu1.20.04.4 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu1 | 2:4.15.13+dfsg-0ubuntu1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm13 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm13 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm14 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm14 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm2 | 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm3 | 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm3 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm1 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm1 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm2 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm2 |
| samba | samba | >= 4.16.0 < 4.16.8 | 4.16.8 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba regression
vendor_ubuntu·2025-06-30·CVSS 6.5
CVE-2022-3437 [MEDIUM] Samba regression
Title: Samba regression
Summary: USN-7582-1 introduced a regression in Samba.
USN-7582-1 fixed vulnerabilities in Samba. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attack
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2025-06-19·CVSS 6.5
CVE-2023-34966 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this issue
to escalate privileges. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-45141)
Florent Saudel discovered that S
Microsoft
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak Vulnerable Samba Active Directory
vendor_msrc·2023-03-14·CVSS 9.8
CVE-2022-45141 [CRITICAL] CWE-326 Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak Vulnerable Samba Active Directory
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VE
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2023-03-08·CVSS 6.5
CVE-2022-37966 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Channel. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-38023)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to
Ubuntu
Samba regression
vendor_ubuntu·2023-01-26·CVSS 5.9
[MEDIUM] Samba regression
Title: Samba regression
Summary: USN 5822-1 introduced regressions on Ubuntu 20.04 LTS.
USN-5822-1 fixed vulnerabilities in Samba. The update for Ubuntu 20.04 LTS
introduced regressions in certain environments. Pending investigation of
these regressions, this update temporarily reverts the security fixes.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2023-01-24·CVSS 5.9
CVE-2022-37966 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Red Hat
samba: Samba AD DC using Heimdal can be forced to issue rc4-hmac encrypted Kerberos tickets
vendor_redhat·2022-12-16·CVSS 9.8
CVE-2022-45141 [CRITICAL] CWE-326 samba: Samba AD DC using Heimdal can be forced to issue rc4-hmac encrypted Kerberos tickets
samba: Samba AD DC using Heimdal can be forced to issue rc4-hmac encrypted Kerberos tickets
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
Statement: The samba package as shipped with Red Hat Enterprise Linux 6, 7, 8 and 9 and Red Hat Gluster is not affected by this issue as Red Hat doesn't provide the AD domain controller capability with it.
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Package: samba (Red Hat Enterprise Linux 8) - Not a
Debian
CVE-2022-45141: samba - Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was dis...
vendor_debian·2022·CVSS 9.8
CVE-2022-45141 [CRITICAL] CVE-2022-45141: samba - Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was dis...
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
Scope: local
bookworm: resolved (fixed in 2:4.16.0+dfsg-2)
bullseye: open
forky: resolved (fixed in 2:4.16.0+dfsg-2)
sid: resolved (fixed in 2:4.16.0+dfsg-2)
trixie: resolved (fixed in 2:4.16.0+dfsg-2)
OSV
samba regression
osv·2025-06-30·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba regression
samba regression
USN-7582-1 fixed vulnerabilities in Samba. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this
issue to escalate privileges. This
OSV
samba vulnerabilities
osv·2025-06-19·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this issue
to escalate privileges. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-45141)
Florent Saudel discovered that Samba incorrectly handled certain Spotlight
requests. A remote
OSV
samba vulnerabilities
osv·2023-03-08·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Channel. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-38023)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE
GHSA
GHSA-g5hg-3x62-v52f: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that r
ghsa_unreviewed·2023-03-07
CVE-2022-45141 [CRITICAL] CWE-326 GHSA-g5hg-3x62-v52f: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that r
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
OSV
CVE-2022-45141: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that r
osv·2023-03-06·CVSS 9.8
CVE-2022-45141 [CRITICAL] CVE-2022-45141: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that r
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
OSV
samba regression
osv·2023-01-26·CVSS 5.9
[MEDIUM] samba regression
samba regression
USN-5822-1 fixed vulnerabilities in Samba. The update for Ubuntu 20.04 LTS
introduced regressions in certain environments. Pending investigation of
these regressions, this update temporarily reverts the security fixes.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrec
OSV
samba vulnerabilities
osv·2023-01-24·CVSS 5.9
CVE-2021-20251 [MEDIUM] samba vulnerabilities
samba vulnerabilities
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Channel. A remote attacker could possibly use this issue to e
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-06
Published