Related Vulnerabilities: CVE-2022-32744  

A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.

Description

A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.

Statement

Red Hat Enterprise Linux is not affected by this flaw as Samba AD (Active Directory) doesn't get built in RHEL.

Red Hat Enterprise Linux is not affected by this flaw as Samba AD (Active Directory) doesn't get built in RHEL.

Additional Information

  • Bugzilla 2108205: CVE-2022-32744 samba: AD users can forge password change requests for any user
  • CWE-290: Authentication Bypass by Spoofing
  • FAQ: Frequently asked questions about CVE-2022-32744