CVE-2020-25717
Vulnerability Summary
Timeline
Description
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- v2.0•HIGH•Score: 8.5AV:N/AC:L/Au:S/C:C/I:C/A:N
EPSS Trends
Current EPSS score: 1.63%• Percentile: 75%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Systems
- alpine•samba
≥ 3.0.0, < 4.13.17-r0 | ≥ 3.0.0, < 4.14.12-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0 | ≥ 3.0.0, < 4.15.2-r0
- canonical•ubuntu_linux
18.04 | 20.04 | 21.04 | 21.10
- debian•samba
< 2:4.13.13+dfsg-1~deb11u2 | < 2:4.13.14+dfsg-1 | < 2:4.13.14+dfsg-1 | < 2:4.13.14+dfsg-1
- debian•debian_linux
9.0 | 10.0
- fedoraproject•fedora
33 | 34 | 35
- redhat•codeready_linux_builder
na
- redhat•enterprise_linux
7.0 | 8.0
- redhat•enterprise_linux_desktop
7.0
- redhat•enterprise_linux_eus
8.2 | 8.4
- redhat•enterprise_linux_for_ibm_z_systems
7.0 | 8.0
- redhat•enterprise_linux_for_ibm_z_systems_eus
8.2 | 8.4
- redhat•enterprise_linux_for_power_big_endian
7.0
- redhat•enterprise_linux_for_power_little_endian
7.0 | 8.0
- redhat•enterprise_linux_for_power_little_endian_eus
8.2 | 8.4
- redhat•enterprise_linux_for_scientific_computing
7.0
- redhat•enterprise_linux_resilient_storage
7.0
- redhat•enterprise_linux_server
7.0
- redhat•enterprise_linux_server_aus
8.2 | 8.4
- redhat•enterprise_linux_server_tus
8.4
- redhat•enterprise_linux_server_update_services_for_sap_solutions
8.2 | 8.4
- redhat•enterprise_linux_tus
8.2
- redhat•enterprise_linux_workstation
7.0
- redhat•gluster_storage
3.0 | 3.5
- redhat•openstack
13 | 16.1 | 16.2
- redhat•virtualization
4.0
- redhat•virtualization_host
4.0
- samba•samba
≥ 3.0.0, < 4.13.14 | ≥ 4.14.0, < 4.14.10 | ≥ 4.15.0, < 4.15.2