CyberRota Analysis
AI-GeneratedA critical vulnerability in FreeIPA allows authenticated Active Directory users to bypass authentication for FreeIPA services, such as the portal, SMB server, and LDAP directory, by impersonating a client name in the Ticket Granting Service (TGS). This occurs due to the lack of verification for Privilege Attribute Certificate (PAC) certificates, enabling privilege escalation within the FreeIPA domain. Organizations using FreeIPA in conjunction with Active Directory should prioritize immediate remediation to mitigate the risk of unauthorized access and privilege escalation.
Original NVD Description
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
Related CVEs
Other vulnerabilities affecting the same vendor(s)