Vulnerabilidad · Publicado 01/09/2026
Una falla de neutralización de caracteres especiales en yast2-samba-client (versiones hasta 5.0.4) permite a un atacante con control sobre un controlador de dominio Active Directory malicioso ejecutar comandos arbitrarios con privilegios root en máquinas siendo unidas al dominio. Afecta directamente servidores Linux en entornos corporativos que integran Active Directory, común en infraestructuras híbridas de LATAM con dominios Windows centralizados.
Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being joined to that domain. This issue affects yast2-samba-client through 5.0.4.
Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-78
Publicado en NIST NVD.