CVE-2022-38023: Netlogon RPC Elevation of Privilege Vulnerability
Netlogon RPC Elevation of Privilege Vulnerability
Other sources
The "RC4" protection of the NetLogon Secure channel uses the same algorithms as rc4-hmac cryptography in Kerberos, and so must also be assumed to be weak.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.15.13 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.16.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26623Patch KB5028224 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21063Fixed in 6.3.9600.21075Patch KB5028223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24374Patch KB5028233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22175Patch KB5028226 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4645Patch KB5028168 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1850Patch KB5028171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6085Patch KB5028169
Event History
Frequently Asked Questions
What is CVE-2022-38023?
CVE-2022-38023 is a Netlogon RPC Elevation of Privilege Vulnerability.
Which software are affected by CVE-2022-38023?
Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, and Windows Server 2022 are affected by CVE-2022-38023. Samba versions 4.15.13 to 4.16.8 and 4.17.0 to 4.17.4 are also affected.
What is the severity of CVE-2022-38023?
The severity of CVE-2022-38023 is high, with a CVSS score of 8.1.
How can I fix CVE-2022-38023 on Windows Server 2008 R2?
You can apply the security patch KB5028240 from Microsoft's official website to fix CVE-2022-38023 on Windows Server 2008 R2.
Where can I find more information about CVE-2022-38023?
You can find more information about CVE-2022-38023 on the Microsoft Security Response Center (MSRC) website, as well as on the Red Hat Bugzilla and Red Hat Access websites.