V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2025-4404
AST
CriticalConfirmedExploit available

This update upgrades freeipa to version 4.12.4-alt1. Security Fix(es): * BDU:2025-04863: Уязвимость централизованной системы по управлению …

CVSS
9.1
Critical
EPSS
0.00
p52
Published
2025-01-01
Updated
2025-01-01
Description

This update upgrades freeipa to version 4.12.4-alt1. Security Fix(es): * BDU:2025-04863: Уязвимость централизованной системы по управлению идентификацией пользователей FreeIPA, связанная с неправильным контролем доступа, позволяющая нарушителю повысить свои привилегии до уровня администратора домена и оказать воздействие на конфиденциальность целостность и доступость защищаемой информации * CVE-2025-4404: A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

Tags · CWE
CWE-1220
CAPEC-1
CAPEC-180
Affected products
FreeipaFreeipaFreeipaFreeipaFreeipa-clientFreeipa-client-automountFreeipa-client-commonFreeipa-client-epnFreeipa-client-sambaFreeipa-commonFreeipa-serverFreeipa-server-commonFreeipa-server-dnsFreeipa-server-trust-adPython3-module-freeipaPython3-module-ipaclientPython3-module-ipaserverPython3-module-ipatests
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p52
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
CVE-2025-4404
github-poc · https://github.com/Im10n/CVE-2025-4404-POC
Enterprise
Affected software
ProductVendorStatus
freeipaTracked
freeipaTracked
freeipaTracked
freeipaTracked
freeipa-clientTracked
freeipa-client-automountTracked
freeipa-client-commonTracked
freeipa-client-epnTracked
freeipa-client-sambaTracked
freeipa-commonTracked
freeipa-serverTracked
freeipa-server-commonTracked
freeipa-server-dnsTracked
freeipa-server-trust-adTracked
python3-module-freeipaTracked
python3-module-ipaclientTracked
python3-module-ipaserverTracked
python3-module-ipatestsTracked