Skip to main content

Samba Releases Security Updates

Security updates address one High and two Medium severity vulnerabilities in multiple versions of Samba

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates address one High and two Medium severity vulnerabilities in multiple versions of Samba


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Samba has released security updates to address one High and two Medium severity vulnerabilities in multiple versions of Samba. The High severity vulnerability known as CVE-2023-0614 has a CVSSv3 score of 7.7 and relates to confidential attribute disclosure via LDAP filters. An attacker could obtain confidential BitLocker recovery keys from a Samba Active Directory Domain Controller (AD DC).


Remediation advice

Affected organisations are encouraged to review Samba's security advisories and to apply the relevant updates where applicable.


Remediation steps

Type Step
Patch

CVE-2023-0225 | Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users


https://www.samba.org/samba/security/CVE-2023-0225.html
Patch

CVE-2023-0922 | Samba AD DC admin tool samba-tool sends passwords in cleartext


https://www.samba.org/samba/security/CVE-2023-0922.html
Patch

CVE-2023-0614 | Access controlled AD LDAP attributes can be discovered


https://www.samba.org/samba/security/CVE-2023-0614.html


Last edited: 3 April 2023 12:53 pm