CVE-2025-4404
published 2025-06-17CVE-2025-4404: A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the…
PriorityP354critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
1.83%
76.4th percentile
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeipa | < freeipa 4.12.4-1 (forky) | freeipa 4.12.4-1 (forky) |
| debian | freeipa | — | — |
| freeipa | freeipa | >= 0 < 4.12.4-1 | 4.12.4-1 |
| freeipa | freeipa | >= 0 < 4.12.4-1 | 4.12.4-1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
osv9.1CRITICAL
vendor_debian9.1LOW
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-7493: A privilege escalation flaw from host to domain administrator was found in FreeIPA
osv·2025-09-30·CVSS 9.1
CVE-2025-7493 [CRITICAL] CVE-2025-7493: A privilege escalation flaw from host to domain administrator was found in FreeIPA
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
GHSA
GHSA-vm59-52f9-r52r: A privilege escalation flaw from host to domain administrator was found in FreeIPA
ghsa_unreviewed·2025-09-30·CVSS 9.1
CVE-2025-7493 [CRITICAL] CWE-1220 GHSA-vm59-52f9-r52r: A privilege escalation flaw from host to domain administrator was found in FreeIPA
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
OSV
CVE-2025-4404: A privilege escalation from host to domain vulnerability was found in the FreeIPA project
osv·2025-06-17·CVSS 9.1
CVE-2025-4404 [CRITICAL] CVE-2025-4404: A privilege escalation from host to domain vulnerability was found in the FreeIPA project
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
GHSA
GHSA-w66p-wgwc-mqmw: A privilege escalation from host to domain vulnerability was found in the FreeIPA project
ghsa_unreviewed·2025-06-17
CVE-2025-4404 [CRITICAL] CWE-1220 GHSA-w66p-wgwc-mqmw: A privilege escalation from host to domain vulnerability was found in the FreeIPA project
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
Red Hat
FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
vendor_redhat·2025-09-30·CVSS 9.1
CVE-2025-7493 [CRITICAL] CWE-1220 FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniquenes
Red Hat
freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
vendor_redhat·2025-06-17·CVSS 9.1
CVE-2025-4404 [CRITICAL] CWE-1220 freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the
Debian
CVE-2025-4404: freeipa - A privilege escalation from host to domain vulnerability was found in the FreeIP...
vendor_debian·2025·CVSS 9.1
CVE-2025-4404 [CRITICAL] CVE-2025-4404: freeipa - A privilege escalation from host to domain vulnerability was found in the FreeIP...
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
Scope: local
bookworm: open
forky: resolved (fixed in 4.12.4-1)
sid: resolved (fixed in 4.12.4-1)
trixie: resolved (fixed in 4.12.4-1)
Debian
CVE-2025-7493: freeipa - A privilege escalation flaw from host to domain administrator was found in FreeI...
vendor_debian·2025·CVSS 9.1
CVE-2025-7493 [CRITICAL] CVE-2025-7493: freeipa - A privilege escalation flaw from host to domain administrator was found in FreeI...
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
Scope: local
bookworm: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-7493 FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
bugzilla·2025-08-19·CVSS 9.1
CVE-2025-7493 [CRITICAL] CVE-2025-7493 FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
CVE-2025-7493 FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
Although CVE-2025-4404 fixed the lack of verification for the uniqueness of the LDAP attribute krbCanonicalName in FreeIPA, it doesn't prevent to achieve the same privilege escalation by using the the root kbrcanonicalname.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Via RHSA-2025:17086 https://access.redhat.com/errata/RHSA-2025:17086
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Via RHSA-2025:17087 https://access.redhat.com/errata/RHSA-2025:17087
---
This issue has been addressed in the following products:
Red Hat Enterprise Linu
Bugzilla
CVE-2025-4404 freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
bugzilla·2025-05-06·CVSS 9.1
CVE-2025-4404 [CRITICAL] CVE-2025-4404 freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
CVE-2025-4404 freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA
The lack of verification for the uniqueness of the LDAP attribute krbCanonicalName in FreeIPA may lead to privilege escalation from host to domain admin.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Via RHSA-2025:9185 https://access.redhat.com/errata/RHSA-2025:9185
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Via RHSA-2025:9193 https://access.redhat.com/errata/RHSA-2025:9193
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.2 Advanced Update Support
Via RHSA-2025:9194 https://access.re
https://access.redhat.com/errata/RHSA-2025:9184https://access.redhat.com/errata/RHSA-2025:9185https://access.redhat.com/errata/RHSA-2025:9186https://access.redhat.com/errata/RHSA-2025:9187https://access.redhat.com/errata/RHSA-2025:9188https://access.redhat.com/errata/RHSA-2025:9189https://access.redhat.com/errata/RHSA-2025:9190https://access.redhat.com/errata/RHSA-2025:9191https://access.redhat.com/errata/RHSA-2025:9192https://access.redhat.com/errata/RHSA-2025:9193https://access.redhat.com/errata/RHSA-2025:9194https://access.redhat.com/security/cve/CVE-2025-4404https://bugzilla.redhat.com/show_bug.cgi?id=2364606https://pagure.io/freeipa/c/6b9400c135ed16b10057b350cc9ce42aa0e862d4https://pagure.io/freeipa/c/796ed20092d554ee0c9e23295e346ec1e8a0bf6ehttp://www.openwall.com/lists/oss-security/2025/09/30/6
2025-06-17
Published