CVE-2020-25720
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 17, 2024
Updated: Nov 18, 2024
CWE ID 264
Summary
CVE-2020-25720 is a vulnerability affecting Samba, a commonly used file-sharing software. Delegated administrators with the ability to create new objects in Active Directory can manipulate these objects' attributes, even sensitive ones, due to a lack of proper Access Control Lists (ACLs) during creation. The administrator becomes the 'creator owner' of the object, retaining significant rights that may not be fully understood, potentially leading to unintended privilege escalation or security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.