|Title:||SAMBA Kerberos Mutual Authentication Vulnerability|
|Affected Products:||PZOS – 6.3.X versions through 22.214.171.124 and 7.X versions through 126.96.36.199|
The SAMBA component of PZOS software contains a vulnerability in which an attacker may impersonate a trusted server, and, leveraging its position, gain unauthorized domain access.
PZOS uses SAMBA in order to act as a Windows share. A recent mutual authentication vulnerability was recently discovered. A malicious server can impersonate a trusted server due to the bug in the Kerberos authentication code. As a trusted server, the attacker can then gain unauthorized access to the domain. More information is available at CVE-2017-11103.
Upgrades are available for all supported releases. Please consult with Panzura Support on the appropriate upgrade for your environment.