CVE-2023-0614 is a medium-severity vulnerability affecting Samba Active Directory Domain Controllers, allowing an authenticated attacker to potentially disclose confidential BitLocker recovery keys. This flaw is an insufficient fix for a previous LDAP filter vulnerability (CVE-2018-10919). With a CVSS score of 6.5, it presents a high confidentiality impact with low attack complexity and no user interaction required. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.16.10CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.17.0, < 4.17.7CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
4.18.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.18.0:-:*:*:*:*:*:* | ||
4.18.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.18.0:rc1:*:*:*:*:*:* | ||
4.18.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.18.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-0614
Oct 8, 2024The fix in 4.6.16 4.7.9 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.
Apr 11, 2023samba: Access controlled AD LDAP attributes can be discovered
Mar 29, 2023