CVE-2022-32746 is a use-after-free vulnerability in the Samba AD LDAP server, specifically within its AD DC database audit logging module, affecting Samba products. This flaw allows an authenticated attacker to access freed memory when modifying privileged attributes like userAccountControl. Rated Medium (CVSS 5.4), it has a low impact on integrity and availability, with no confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.3.0, < 4.14.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.15.0, < 4.15.9CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.16.0, < 4.16.4CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-32746
Dec 10, 2024CVE-2022-32746
Nov 12, 2024CVE-2022-32746
Oct 8, 2024AS-2022-014: Samba
Dec 27, 2022A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes such as userAccountControl.
Aug 9, 2022samba: AD users can induce a use-after-free in the server process with an LDAP add or modify request
Jul 27, 2022