A vulnerability in Samba allowing any user to change the password.

Corrective releases for Samba 4.16.4, 4.15.9, and 4.14.14 have been published, addressing 5 vulnerabilities. The release of package updates in distributions can be tracked on the following pages: Debian, Ubuntu, RHEL, SUSE, Arch, FreeBSD.

The most critical vulnerability (CVE-2022-32744) allows users in an Active Directory domain to change any user's password, including the administrator's password, thus gaining full control over the domain. This issue stems from the fact that KDC accepts kpasswd requests encrypted with any known key.

An attacker with access to domain, can send a spoofed request to set a new password on behalf of another user, encrypting it with their key, and the KDC will process it without verifying the key match of the account. Domain controller keys operating in read-only mode (RODC) can also be used to send spoofed requests, which do not have the authority to change passwords. A workaround protection can be implemented by disabling kpasswd protocol support by adding "kpasswd port = 0" in smb.conf.

Other vulnerabilities:

  • CVE-2022-32746 — Active Directory users can trigger a use-after-free condition in the server process by sending specially crafted 'add' or 'modify' LDAP requests. This issue arises because the audit logging module accesses the content of the LDAP message after the database module has freed the memory allocated for the message. To carry out the attack, rights to add or modify certain privileged attributes like userAccountControl are required.
  • CVE-2022-2031 — Active Directory users can bypass some restrictions in the domain controller. The KDC and kpasswd service can decrypt each other's tickets since they share a common set of keys and accounts. Consequently, a user requesting a password change can use the ticket obtained to access other services.
  • CVE-2022-32745 — Active Directory users can crash the server process by sending 'add' or 'modify' LDAP requests, leading to access of uninitialized data.
  • CVE-2022-32742 — Information leakage concerning memory content server through manipulations with the SMB1 protocol. The SMB1 client, having write access to the shared storage, can create conditions for writing chunks of the server process's memory to a file or sending it to the printer. The attack is carried out by sending a 'write' request specifying an incorrect range. This issue affects only Samba branches up to 4.11 (in branch 4.11, SMB1 support is disabled by default).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster