Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

April Vulnerability of the Month: Password Free-for-All Via Samba Active Directory Domain Controller Vulnerability

Every month, we ask our researchers to nominate a vulnerability of the month. Novelty, sophistication or just plain weirdness are some of the potential criteria for selecting a vulnerability of the month. After the nominations are collected, the candidates are shortlisted and voted on by our 70-plus-member research organization, combining the total experience and knowledge of Tenable Research to identify the vulnerability of the month.

Background

In mid-March, Samba released an advisory on two critical vulnerabilities. One of these, CVE-2018-1057, allows unprivileged users to change any user password including privileged service and admin user accounts. Researcher Björn Baumbach from SerNet is credited with discovering this vulnerability.

What makes this the vulnerability of the month?

Samba administrators were likely eager to mitigate this vulnerability in mid-March based on the serious implications of CVE-2018-1057 and the other vulnerability included in the patch release. Samba is free, open-source software for file and print services that helps integrate Linux/Unix servers and desktops into Active Directory environments. These qualities have made Samba very popular with widespread prevalence, meaning any vulnerabilities in Samba have potentially wide-reaching impact. One common application of Samba is to provide file and printer sharing services for Linux-based network attached storage (NAS) and storage area network (SAN) systems. Samba file servers can store diverse data, including sensitive data, personally identifiable information and intellectual property.

CVE-2018-1057, in particular, has both accidental and malicious implications. On the accidental, potentially mischievous side, authenticated users could change their coworkers’ passwords, locking them out as a fun office prank.

More seriously, malicious attackers who have gained any legitimate credentials, for example via social engineering, can change the passwords of admin and domain controller accounts and thereby take control of them, escalating their privileges. Using a simple phishing campaign, coupled with this vulnerability, an attacker could navigate through targeted environments horizontally and vertically throughout the organization with minimal effort.

However, attackers don’t have to rely on social engineering or phishing to leverage this vulnerability. Once a machine has been compromised, it can be leveraged to interact with Samba Active Directory Domain Controller (AD DC) and allow the attacker to access accounts with similar or increased permissions.

Vulnerability details

According to the advisory, in all versions of Samba AD DC from 4.0.0 onward, the Lightweight Directory Access Protocol (LDAP) server incorrectly validates permissions to change passwords. This allows authenticated users to change other users' passwords, including administrative users and DCs.

The advisory specifies that “the LDAP server incorrectly validates certain LDAP password modifications against the ‘Change Password’ privilege, but then performs a password reset operation.”

Samba released a patch for Samba versions 4.7.6, 4.6.14 and 4.5.16 and outlined a few workarounds, including revoking change password rights “for 'the world' from all user objects (including computers) in the directory, leaving only the right to change a user's own password.”

Additional resources

Related Posts

Subscribe to the Tenable Blog

Subscribe
Try for Free Buy Now

Try Tenable.io

FREE FOR 30 DAYS

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Sign up now.

Buy Tenable.io

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

65 assets

$2,275

Buy Now

Try for Free Buy Now

Try Nessus Professional Free

FREE FOR 7 DAYS

Nessus® is the most comprehensive vulnerability scanner on the market today. Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy Nessus Professional

Nessus® is the most comprehensive vulnerability scanner on the market today. Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, email, community and chat support 24 hours a day, 365 days a year. Full details here.

Try for Free Buy Now

Try Tenable.io Web Application Scanning

FREE FOR 30 DAYS

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable.io platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Buy Tenable.io Web Application Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try for Free Contact Sales

Try Tenable.io Container Security

FREE FOR 30 DAYS

Enjoy full access to the only container security offering integrated into a vulnerability management platform. Monitor container images for vulnerabilities, malware and policy violations. Integrate with continuous integration and continuous deployment (CI/CD) systems to support DevOps practices, strengthen security and support enterprise policy compliance.

Buy Tenable.io Container Security

Tenable.io Container Security seamlessly and securely enables DevOps processes by providing visibility into the security of container images – including vulnerabilities, malware and policy violations – through integration with the build process.

Learn More about Industrial Security

Get a Demo of Tenable.sc

Please fill out the form below with your contact information and a sales representative will contact you shortly to schedule a demo. You may also include a short comment (limited to 255 characters). Please note that fields with asterisks (*) are mandatory.

Try for Free Contact Sales

Try Tenable Lumin

FREE FOR 30 DAYS

Visualize and explore your Cyber Exposure, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Buy Tenable Lumin

Contact a Sales Representative to see how Lumin can help you gain insight across your entire organization and manage cyber risk.