AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-1057

HIGH · CVSS 8.8 EPSS 10.11%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-03-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-1057
Severity
HIGH
CVSS
8.8
EPSS
10.11%

Original NVD Description

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).