CRITICAL🇵🇱 Wersja polska

CVE-2022-45141

CVSS 9.8v3.1pub. 2023-03-06upd. 2025-03-06

Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Samba

    APP
    Samba
    < 4.15.134.16.0 – 4.16.8 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-7494CRITICAL9.8⚠ KEVPL ✓same product

Samba — RCE poprzez wgranie i wykonanie biblioteki współdzielonej

CVE-2026-4408CRITICAL9.0PL ✓same product

Samba: RCE przez command injection w 'check password script' z podstawieniem %u

CVE-2026-4480CRITICAL9.0PL ✓same product

Samba: command injection w podsystemie drukowania przez podstawienie %J

CVE-2023-3961CRITICAL9.1PL ✓same product

Path traversal w Samba — nieautoryzowany dostęp przez Unix domain socket

CVE-2022-44640CRITICAL9.8PL ✓same product

Zdalne wykonanie kodu w Heimdal przez błąd double-free w kodeku ASN.1