VulnerabilityModified
CVE-2020-25722
An attacker could use this flaw to cause total domain compromise.
HIGH 8.8EPSS 1.61%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.61% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- samba/samba · debian/debian linux · fedoraproject/fedora · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2019764Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2020-25722.htmlMitigation, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2019764Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2020-25722.htmlMitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.