CRITICAL🇵🇱 Wersja polska

CVE-2025-4404

CVSS 9.1v3.1pub. 2025-06-17upd. 2026-06-30

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

🤖 AI Analysis
How it works

FreeIPA does not verify the uniqueness of the `krbCanonicalName` attribute for an administrator account. A user can create a service with the same canonical name as the admin@REALM account. After performing the attack, it is possible to obtain a Kerberos ticket assigned to this service, which contains admin@REALM credentials. As a result, the attacker impersonates the domain administrator and gains full permissions to manage the REALM.

Impact

An attacker can perform arbitrary administrative tasks in the Kerberos domain, leading to access to sensitive data and their exfiltration.

Mitigation & patch

Apply patches available from the vendor according to Red Hat references: RHSA-2025:9184, RHSA-2025:9185, RHSA-2025:9186, RHSA-2025:9187, RHSA-2025:9188.

Who is affected

FreeIPA package — versions indicated in vendor references (Red Hat errata RHSA-2025:9184, RHSA-2025:9185, RHSA-2025:9186, RHSA-2025:9187, RHSA-2025:9188)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References