CVE-2012-2111: Medium severity samba vulnerability
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2111?
CVE-2012-2111 has a medium severity rating due to the potential for remote authenticated users to modify the privileges database.
How do I fix CVE-2012-2111?
To fix CVE-2012-2111, upgrade Samba to versions 3.4.17, 3.5.15, or 3.6.5 or later.
Which versions of Samba are affected by CVE-2012-2111?
CVE-2012-2111 affects Samba versions 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5.
What impact does CVE-2012-2111 have on system security?
CVE-2012-2111 allows authenticated users to potentially gain unauthorized access to modify account privileges, impacting system security.
Do I need to apply immediate action for CVE-2012-2111?
Yes, it is recommended to apply the appropriate updates as soon as possible to mitigate the risks associated with CVE-2012-2111.