First published: Mon Mar 06 2023(Updated: )
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | <4.15.13 | |
Samba Samba | >=4.16.0<4.16.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45141 is the identifier for the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability.
CVE-2022-45141 has a severity rating of 9.8, which is considered critical.
Samba versions 4.15.13 and Samba versions 4.16.0 to 4.16.8 are affected by CVE-2022-45141.
CVE-2022-45141 allows attackers to issue rc4-hmac encrypted tickets on vulnerable Samba Active Directory DCs.
To fix CVE-2022-45141, it is recommended to update Samba to a version that is not affected by the vulnerability.