Unknown
CVE-2021-44142
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-44142
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide “…enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver.” Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Add Assessment
Ratings
Technical Analysis
A July 2024 bulletin from multiple U.S. government agencies indicates that North Korean state-sponsored attackers have demonstrated interest in this vulnerability — not immediately clear whether it was exploited outright or used in some other capacity: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
Not on CISA KEV as of August 7, 2024.
Would you also like to delete your Exploited in the Wild Report?
Delete Assessment Only Delete Assessment and Exploited in the Wild ReportCVSS V3 Severity and Metrics
General Information
Vendors
- canonical,
- debian,
- fedoraproject,
- redhat,
- samba,
- synology
Products
- codeready linux builder -,
- debian linux 10.0,
- debian linux 11.0,
- diskstation manager,
- enterprise linux 7.0,
- enterprise linux 8.0,
- enterprise linux desktop 7.0,
- enterprise linux eus 8.2,
- enterprise linux eus 8.4,
- enterprise linux for ibm z systems 7.0,
- enterprise linux for ibm z systems 8.0,
- enterprise linux for ibm z systems eus 8.2,
- enterprise linux for ibm z systems eus 8.4,
- enterprise linux for power big endian 7.0,
- enterprise linux for power little endian 7.0,
- enterprise linux for power little endian 8.0,
- enterprise linux for power little endian eus 8.2,
- enterprise linux for power little endian eus 8.4,
- enterprise linux for scientific computing 7.0,
- enterprise linux resilient storage 7.0,
- enterprise linux server 7.0,
- enterprise linux server 8.1,
- enterprise linux server aus 8.2,
- enterprise linux server aus 8.4,
- enterprise linux server tus 8.2,
- enterprise linux server tus 8.4,
- enterprise linux server update services for sap solutions 8.1,
- enterprise linux server update services for sap solutions 8.2,
- enterprise linux server update services for sap solutions 8.4,
- enterprise linux workstation 7.0,
- fedora 34,
- fedora 35,
- gluster storage 3.5,
- samba,
- ubuntu linux 14.04,
- ubuntu linux 16.04,
- ubuntu linux 18.04,
- ubuntu linux 20.04,
- ubuntu linux 21.10,
- virtualization host 4.0
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: