Impact
The trust-fetch-domains command is protected by a read-only trust object permission rather than a trust‑administration permission, allowing any authenticated but non‑privileged IPA user to trigger an Active Directory trust refresh controlled by the attacker. This results in unauthorized writes to trusted‑domain and ID‑range identity data in the LDAP directory, compromising trust relationship integrity and potentially enabling further exploitation of the domain. The flaw is a classic privilege‑escalation weakness (CWE‑863).
Affected Systems
Red Hat Enterprise Linux 6 through 10 running FreeIPA with an Active Directory trust configured are affected. The issue arises when the server’s trust‑fetch-domains command is invoked by a non‑privileged user, regardless of specific FreeIPA versions beyond those operating systems.
Risk and Exploitability
With a CVSS score of 8.2 the vulnerability poses a high risk, and the EPSS score of less than 1% indicates a very low probability of exploitation at present. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated LDAP user who has limited privileges but can send commands to the server; thus the exploitation requires an authenticated session, not a local or OS privilege escalation.
OpenCVE Enrichment