cbcvebase.
CVE-2023-4154
published 2023-11-07

CVE-2023-4154: A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only…

PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.15%
63.6th percentile
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which should only replicate some passwords, can gain access to all domain secrets, including the vital krbtgt, effectively eliminating the RODC / DC distinction. Furthermore, the vulnerability fails to account for error conditions (fail open), like out-of-memory situations, potentially granting access to secret attributes, even under low-privileged attacker influence.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiansamba< samba 2:4.17.12+dfsg-0+deb12u1 (bookworm)samba 2:4.17.12+dfsg-0+deb12u1 (bookworm)
sambasamba>= 0 < 2:4.17.12+dfsg-0+deb12u12:4.17.12+dfsg-0+deb12u1
sambasamba>= 0 < 2:4.19.1+dfsg-12:4.19.1+dfsg-1
sambasamba>= 0 < 2:4.19.1+dfsg-12:4.19.1+dfsg-1
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.72:4.15.13+dfsg-0ubuntu0.20.04.7
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.62:4.15.13+dfsg-0ubuntu0.20.04.6
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu1.52:4.15.13+dfsg-0ubuntu1.5
sambasamba>= 0 < 2:4.18.6+dfsg-1ubuntu2.12:4.18.6+dfsg-1ubuntu2.1
sambasamba>= 4.0.0 < 4.17.124.17.12
sambasamba>= 4.18.0 < 4.18.84.18.8
sambasamba>= 4.19.0 < 4.19.14.19.1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.