8.5
CVSSv2

CVE-2014-8143

Published: 17/01/2015 Updated: 08/09/2017
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Samba 4.0.x prior to 4.0.24, 4.1.x prior to 4.1.16, and 4.2.x prior to 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 4.0.12

samba samba 4.0.13

samba samba 4.0.14

samba samba 4.0.20

samba samba 4.0.21

samba samba 4.0.0

samba samba 4.0.1

samba samba 4.0.17

samba samba 4.0.18

samba samba 4.0.3

samba samba 4.0.4

samba samba 4.1.1

samba samba 4.1.10

samba samba 4.1.4

samba samba 4.1.5

samba samba 4.2.0

samba samba 4.0.7

samba samba 4.0.8

samba samba 4.1.14

samba samba 4.1.15

samba samba 4.1.8

samba samba 4.1.9

samba samba 4.0.15

samba samba 4.0.16

samba samba 4.0.22

samba samba 4.0.23

samba samba 4.0.9

samba samba 4.1.0

samba samba 4.1.2

samba samba 4.1.3

samba samba 4.0.10

samba samba 4.0.11

samba samba 4.0.19

samba samba 4.0.2

samba samba 4.0.5

samba samba 4.0.6

samba samba 4.1.11

samba samba 4.1.12

samba samba 4.1.13

samba samba 4.1.6

samba samba 4.1.7

Vendor Advisories

A security issue was fixed in Samba ...
Debian Bug report logs - #776993 samba: CVE-2014-8143: Elevation of privilege to Active Directory Domain Controller Package: src:samba; Maintainer for src:samba is Debian Samba Maintainers <pkg-samba-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 3 Feb 2015 21:12:01 U ...
Debian Bug report logs - #779033 samba: CVE-2015-0240: unexpected code execution in smbd Package: src:samba; Maintainer for src:samba is Debian Samba Maintainers <pkg-samba-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 23 Feb 2015 13:42:01 UTC Severity: grave Tags: f ...
Samba 40x before 4024, 41x before 4116, and 42x before 42rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creat ...