PT-2022-5459 · Samba+7 · Samba Active Directory Dc+9

Published

2022-11-08

·

Updated

2026-02-22

·

CVE-2022-37966

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Kerberos versions prior to the update that addresses the RC4-HMAC vulnerability Samba Active Directory DC (affected versions not specified)
Description The issue is related to the implementation of the Kerberos protocol in Windows operating systems, which uses the RC4-HMAC cryptographic algorithm containing defects. This allows a remote attacker to elevate their privileges. The vulnerability can affect the system, and its exploitation may have significant consequences. Microsoft introduced updates to the Kerberos protocol to address vulnerabilities like this one, aiming to phase out the weak RC4 cipher in favor of AES encryption for Kerberos tickets.
Recommendations For Windows Kerberos versions prior to the update that addresses the RC4-HMAC vulnerability: Update to a version that includes the fix for the RC4-HMAC vulnerability, which phases out the weak RC4 cipher in favor of AES encryption for Kerberos tickets. For Samba Active Directory DC: Consider changing the 'kerberos encryption types' configuration to avoid forcing rc4-hmac as a client, allowing the use of stronger ciphers like aes128-cts-hmac-sha1-96 and/or aes256-cts-hmac-sha1-96. As a temporary workaround, consider restricting the use of the RC4-HMAC algorithm until a patch is available.

Fix

Use of a Broken Cryptographic Algorithm

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3352
ALT-PU-2023-1371
ALT-PU-2024-14683
AZL-54678
BDU:2022-06786
CVE-2022-37966
MGASA-2023-0010
OESA-2023-1018
OESA-2023-1019
OPENSUSE-SU-2023_0160-1
OPENSUSE-SU-2023_0163-1
OPENSUSE-SU-2023_0222-1
OPENSUSE-SU-2024:12587-1
SUSE-SU-2023:0014-1
SUSE-SU-2023:0122-1
SUSE-SU-2023:0126-1
SUSE-SU-2023:0160-1
SUSE-SU-2023:0163-1
SUSE-SU-2023:0164-1
SUSE-SU-2023:0222-1
SUSE-SU-2023:0620-1
SUSE-SU-2023_0014-1
USN-5822-1
USN-5822-2
USN-5936-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Samba
Samba Active Directory Dc
Suse
Ubuntu
Windows
Windows Kerberos