A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2019726 | issue tracking third party advisory |
https://www.samba.org/samba/security/CVE-2020-25718.html | vendor advisory |
https://security.gentoo.org/glsa/202309-06 | vendor advisory |