A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2022-02-18T00:00:00
Updated: 2024-08-04T15:40:36.654Z
Reserved: 2020-09-16T00:00:00
Link: CVE-2020-25719
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-18T18:15:08.563
Modified: 2024-11-21T05:18:34.137
Link: CVE-2020-25719
Redhat