CVE-2018-1057 PUBLISHED

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).

EPSS 7.72% · 91.9th percentile

Risk Scores

EPSS Score
7.72%
91.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsamba0, 2:4.1.17+dfsg-4ubuntu2, 2:4.1.20+dfsg-1ubuntu1
Ubuntu:14.04:LTSsamba2:4.3.11+dfsg-0ubuntu0.14.04.1, 2:4.3.11+dfsg-0ubuntu0.14.04.2, 2:4.3.11+dfsg-0ubuntu0.14.04.3

Timeline

References

Open in Interactive Console →