Impact
A privilege escalation flaw was discovered in FreeIPA. The 389-ds directory server enforces a uniqueness constraint on Kerberos principal names but does not correctly handle different representations of the same principal. This omission allows a user who has LDAP write privileges to create a service principal that impersonates an existing privileged one, thereby obtaining Kerberos service tickets for sensitive services. The resulting access could culminate in a full domain compromise.
Affected Systems
Affected systems include Red Hat Enterprise Linux 6, 7, 8, 9 and 10 running FreeIPA, since the vulnerability resides in the FreeIPA LDAP datastore used on those operating‑system releases.
Risk and Exploitability
The flaw carries a CVSS score of 8.7. The EPSS score is 0.00329, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker already possesses LDAP write permissions, after which the attacker can create a rogue service principal that matches an existing privileged principal and impersonate it. Given the high severity and the potential for domain‑wide compromise, the risk is significant until Red Hat releases a patch or an effective mitigation.
OpenCVE Enrichment