Vulnerability Description
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | < 4.15.13 |
Related Weaknesses (CWE)
References
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2022-45141.htmlVendor Advisory
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2022-45141.htmlVendor Advisory
FAQ
What is CVE-2022-45141?
CVE-2022-45141 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory...
How severe is CVE-2022-45141?
CVE-2022-45141 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-45141?
Check the references section above for vendor advisories and patch information. Affected products include: Samba Samba.