Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Samba 3.4.0 <= 3.6.4 Elevate Privileges Vulnerability (CVE-2012-2111)

Information

Severity

Severity

Medium

Family

Family

Privilege escalation

CVSSv2 Base

CVSSv2 Base

6.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

Samba 3.4.x to 3.6.4 are affected by a vulnerability that allows arbitrary users to modify privileges on a file server.

Insight

Insight

Samba versions 3.4.x to 3.6.4 inclusive are affected by a vulnerability that allows arbitrary users to modify privileges on a file server. Security checks were incorrectly applied to the Local Security Authority (LSA) remote procedure calls (RPC) CreateAccount, OpenAccount, AddAccountRights and RemoveAccountRights allowing any authenticated user to modify the privileges database. This is a serious error, as it means that authenticated users can connect to the LSA and grant themselves the 'take ownership' privilege. This privilege is used by the smbd file server to grant the ability to change ownership of a file or directory which means users could take ownership of files or directories they do not own.

Affected Software

Affected Software

Samba versions 3.4.0 through 3.4.16, 3.5.0 through 3.5.14 and 3.6.0 through 3.6.4.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Update to 3.4.17, 3.5.15, 3.6.5 or later.

Common Vulnerabilities and Exposures (CVE)