CVE-2020-25717 is a high-severity flaw in Samba's user mapping functionality, affecting canonical, Debian, Fedora, Red Hat, and Samba products. An authenticated attacker can exploit this vulnerability over the network with low complexity to achieve privilege escalation, potentially leading to high impact on confidentiality and integrity. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for significant impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 4.13.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.14.0, < 4.14.10CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.15.0, < 4.15.2CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2020-25717
Oct 8, 2024A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
Feb 8, 2022samba: Active Directory (AD) domain user could become root on domain members
Nov 9, 2021