Samba Security Updates 18 December 2022

Samba has released security updates to fix multiple vulnerabilities in versions 4.17.4, 4.16.8 and 4.15.13.

The addressed vulnerabilities could allow the remote attacker to gain elevated privileges and take control of affected systems.

Sample of addressed vulnerabilities:

1. Netlogon RPC Privilege Escalation (CVE-2022-38023):

• CVSS: 8.1

• Attack Vector: Network

• Attack Complexity: High

• Privileges Required: None

• User Interaction: None

• Consequences: Gain Privilege

2. Kerberos RC4-HMAC Privilege Escalation (CVE-2022-37966):

• CVSS: 8.1

• Attack Vector: Network

• Attack Complexity: High

• Privileges Required: None

• User Interaction: None

• Consequences: Gain Privilege

Vulnerabilities
  • CVE-2022-38023
  • CVE-2022-37966
  • CVE-2022-37967
  • CVE-2022-45141
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Samba Security Update

References