Impact
An OS command injection flaw in yast2-samba-client allows a malicious actor who can control entries in an Active Directory tree—such as a rogue domain controller or a delegated user—to insert arbitrary characters into an Organizational Unit field. When a machine is joined to the domain, the invalidated value is passed to a system command, giving the attacker the ability to execute commands with root privileges on that host. This flaw is classified as CWE-78.
Affected Systems
SUSE yast2-samba-client version 5.0.4 and earlier are vulnerable. Any system that uses yast2-samba-client to join a domain is at risk if the underlying AD structure can be manipulated by an attacker.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not currently known to be exploited in the wild. The attack requires the ability to inject content into the AD directory, typically through a rogue domain controller or a user with privileges to create objects. Once such content is injected, the domain-joining process can be co-opted to run arbitrary commands as root on the target machine.
OpenCVE Enrichment