CVE-2023-0614: Samba

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

Affected products

  • Samba Samba: from 4.0.0, before 4.16.10 (fixed in 4.16.10); from 4.17.0, before 4.17.7 (fixed in 4.17.7); version 4.18.0 only

Published 2023-04-03. Last modified 2026-06-17.