A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
FreeIPA does not verify the uniqueness of the `krbCanonicalName` attribute for an administrator account. A user can create a service with the same canonical name as the admin@REALM account. After performing the attack, it is possible to obtain a Kerberos ticket assigned to this service, which contains admin@REALM credentials. As a result, the attacker impersonates the domain administrator and gains full permissions to manage the REALM.
An attacker can perform arbitrary administrative tasks in the Kerberos domain, leading to access to sensitive data and their exfiltration.
Apply patches available from the vendor according to Red Hat references: RHSA-2025:9184, RHSA-2025:9185, RHSA-2025:9186, RHSA-2025:9187, RHSA-2025:9188.
FreeIPA package — versions indicated in vendor references (Red Hat errata RHSA-2025:9184, RHSA-2025:9185, RHSA-2025:9186, RHSA-2025:9187, RHSA-2025:9188)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H