CVE-2022-45141

CVSS V2 None CVSS V3 None
Description
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
Overview
  • CVE ID
  • CVE-2022-45141
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-06T23:15:11
  • Last Modified Date
  • 2023-03-13T18:05:10
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 1 OR 4.15.13
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 1 OR 4.16.0 4.16.8
References
Reference URL Reference Tags
https://www.samba.org/samba/security/CVE-2022-45141.html Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 06:01:01 Added to TrackCVE
2023-04-17 06:01:04 Weakness Enumeration new