CVE-2014-8143
Samba 4.0.x < 4.0.24, 4.1.x < 4.1.16, 4.2.x < 4.2rc4 - Privilege Escalation via LDB Manipulation
Title source: llmDescription
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
References (11)
Core 11
Core References
Vendor Advisory vendor-advisory
x_refsource_slackware
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.416326
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html
Patch x_refsource_confirm
https://download.samba.org/pub/samba/patches/security/samba-4.1.15-CVE-2014-8143.patch
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031615
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100596
Patch x_refsource_confirm
https://download.samba.org/pub/samba/patches/security/samba-4.0.23-CVE-2014-8143.patch
Patch, Vendor Advisory x_refsource_confirm
https://www.samba.org/samba/security/CVE-2014-8143
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72278
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62594
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2481-1
Scores
EPSS
0.0490
EPSS Percentile
89.7%
Details
CWE
CWE-264
Status
published
Products (41)
samba/samba
4.0.0
samba/samba
4.0.1
samba/samba
4.0.2
samba/samba
4.0.3
samba/samba
4.0.4
samba/samba
4.0.5
samba/samba
4.0.6
samba/samba
4.0.7
samba/samba
4.0.8
samba/samba
4.0.9
... and 31 more
Published
Jan 17, 2015
Tracked Since
Feb 18, 2026