Skip to main content

Samba Releases Security Updates

One of the five vulnerabilities scores an 8.8 on the CVSSv3 scale and could allow a user to change other users' passwords, leading to full domain takeover

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

One of the five vulnerabilities scores an 8.8 on the CVSSv3 scale and could allow a user to change other users' passwords, leading to full domain takeover


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Samba has released security updates to address five vulnerabilities in multiple versions of Samba, a standard Windows interoperability suite of programs for Linux and Unix. These vulnerabilities include CVE-2022-32744, which has a score of 8.8 on the CVSSv3 scale and could allow an attacker who has gained user privileges to change the passwords of other users, thus enabling full domain takeover.

The other updates address bypassing restrictions on changing passwords, causing a denial-of-service on the server, a memory leak via SMB1, and a use-after-free vulnerability in the server process. An attacker could exploit some of these vulnerabilities to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review the following Samba Security Announcements and apply any relevant updates or workarounds.


Remediation steps

Type Step
Patch

Samba Security Announcement - CVE-2022-2031

Samba AD users can bypass certain restrictions associated with changing passwords


https://www.samba.org/samba/security/CVE-2022-2031.html
Patch

Samba Security Announcement - CVE-2022-32742

Server memory information leak via SMB1


https://www.samba.org/samba/security/CVE-2022-32742.html
Patch

Samba Security Announcement - CVE-2022-32744

Samba AD users can forge password change requests for any user


https://www.samba.org/samba/security/CVE-2022-32744.html
Patch

Samba Security Announcement - CVE-2022-32745

Samba AD users can crash the server process with an LDAP add or modify request


https://www.samba.org/samba/security/CVE-2022-32745.html
Patch

Samba Security Announcement - CVE-2022-32746

Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request


https://www.samba.org/samba/security/CVE-2022-32746.html

Definitive source of threat updates


Last edited: 28 July 2022 5:00 pm