REDHAT-BUG-2305954: Medium severity Microsoft Active Directory vulnerability
A delegated administrator who can create objects in Active Directory, can write to all attributes in that new object, including after the object is created because they own the object. This includes some security-sensitive attributes (less in Samba that in Windows).
Because these rights are due to there being no ACL at creation time and later being the nebulous 'creator owner', the implication that the delegated administrator retains significant rights may not be well understood.
Behaviour removing the implicit rights of creating users to write to all attributes is off by default in Samba and Windows (see CVE-2021-42291 )
(As mentioned in the bug, we developed some other protections for this that landed in the other CVEs, which is why this one didn't get the full security notice treatment).
The details of how to turn this protection on are at: https://support.microsoft.com/en-us/topic/kb5008383-active-directory-permissions-updates-cve-2021-42291-536d5555-ffba-4248-a60e-d6cbc849cde1
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2305954?
REDHAT-BUG-2305954 is considered a high-severity vulnerability due to its potential to expose sensitive attributes in Active Directory.
How do I fix REDHAT-BUG-2305954?
To fix REDHAT-BUG-2305954, ensure that proper permission settings are enforced to limit delegated administrators' access to sensitive attributes.
Who is affected by REDHAT-BUG-2305954?
Users running Microsoft Active Directory or Samba are affected by REDHAT-BUG-2305954.
What are the implications of REDHAT-BUG-2305954?
The implications of REDHAT-BUG-2305954 include the risk of unauthorized data manipulation by delegated administrators.
Is there a patch available for REDHAT-BUG-2305954?
Yes, there are patches and updates available from Red Hat and related vendors to address the vulnerabilities associated with REDHAT-BUG-2305954.