ZeroHour

CVE-2020-25719

CVSS 3.1
7.2 high
EPSS
2%p76
Published
()
Modified
Description

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

Vendors
sambadebianfedoraprojectcanonicalredhat
Products
samba, debian linux, fedora, ubuntu linux, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power big endian, enterprise linux for power little endian, enterprise linux for power little endian eus
Weakness
CWE-287, CWE-362
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.