Privilege escalation can be achieve via Samba.
Does anyone KNOW how to prevent this? I'm not asking for the mechanics (i.e. the steps) on what to do. Right now, I simply want to KNOW if the door can shut (100%/absolutely/positively/guaranteed) on privilege escalation via Samba!
Of course, I KNOW one full-proof way to achieve this - eliminate the service altogether!!!
Thanks in advance!
@Trevor sorry , 100% is not guaranteed unless you remove the service altogether.
Refer : clouddefense.ai/cve/2020/CVE-2020-25717
SELinux, patching, firewall, strong authentication, principle of least privilege, monitoring are the only options which can restrict the door upto say 90-95% but NOT a 100% guarantee !
Red Hat
Learning Community
A collaborative learning environment, enabling open source skill development.