Beveiligingsadvies
CVE-2022-32744
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.