CVE-2022-45141
Samba vulnerability analysis and mitigation

Overview

CVE-2022-45141 affects Heimdal builds of the Samba Active Directory DC prior to Samba 4.16. The vulnerability allows Samba Active Directory DCs to issue rc4-hmac encrypted tickets despite the target server supporting better encryption methods like aes256-cts-hmac-sha1-96. This issue was discovered following Microsoft's disclosure of the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability on November 8, 2022 (Vendor Advisory).

Technical details

The vulnerability stems from a coding error in Heimdal versions that was subsequently addressed in recent versions. In Kerberos authentication, the KDC issues tickets using a key known only to the target server. Due to this vulnerability, an attacking client could select the encryption type and obtain a ticket encrypted with rc4-hmac, which could then be attacked offline. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability allows attackers to force the use of weaker rc4-hmac encryption, potentially enabling offline attacks against the encrypted tickets. This weakness cannot be mitigated by removing rc4-hmac from the server's account (by removing the unicodePwd attribute) as this would break other domain operations, particularly NETLOGON (Vendor Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Samba 4.15.13 and later versions. Administrators are advised to upgrade to these releases or apply the available patches as soon as possible. It's important to note that setting msDS-SupportedEncryptionTypes is not a valid workaround for this issue (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management