CVE-2022-45141
9.8
CRITICAL
CVSS 3.1
EPSS 0.45%
描述
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
如何修補 CVE-2022-45141
要修補 CVE-2022-45141,請將受影響套件升級到下列已修補版本。
- Alpine/samba—升級至 4.15.13-r0 或更新版本
CVE-2022-45141 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 4.16.0, < 4.15.13-r0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |