Synced 19 Jun 2026 07:34 UTC Account
← All products

CVE-2014-8143

HIGH severity · CVSS 8.5 · CWE-264
8.5CVSS HIGH

Summary

Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impact
Exploit probability (EPSS)4%

AV:N/AC:M/Au:S/C:C/I:C/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://download.samba.org/pub/samba/patches/security/samba-4.0.23-CVE-2014-8143.patch ↗