CVE-2020-25720

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 17, 2024
Updated: Nov 18, 2024
CWE ID 264

Summary

CVE-2020-25720 is a vulnerability affecting Samba, a commonly used file-sharing software. Delegated administrators with the ability to create new objects in Active Directory can manipulate these objects' attributes, even sensitive ones, due to a lack of proper Access Control Lists (ACLs) during creation. The administrator becomes the 'creator owner' of the object, retaining significant rights that may not be fully understood, potentially leading to unintended privilege escalation or security risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share