Total vulnerabilities in the database
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
Software | From | Fixed in |
---|---|---|
samba / samba | 4.16.0 | 4.16.4 |
samba / samba | 4.15.0 | 4.15.9 |
samba / samba | 4.3.0 | 4.14.14 |