Vulnerabilities > CVE-2022-32746 - Use After Free vulnerability in Samba

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
LOW
network
low complexity
samba
CWE-416

Summary

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.

Vulnerable Configurations

Part Description Count
Application
Samba
260

Common Weakness Enumeration (CWE)