CVE-2022-32744
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpa
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
HIGH · CVSS 8.8
EPSS 0.00516
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0