CVE-2025-4404

EUVD-2025-18495
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeipa
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-client
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-client-common
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-client-encrypted-dns
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-client-epn
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-client-samba
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-common
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-selinux
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-selinux-luna
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-selinux-nfast
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-server
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-server-common
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-server-dns
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-server-encrypted-dns
RHEL 9
0:4.12.2-14.el9_6.1
fixed
ipa-server-trust-ad
RHEL 9
0:4.12.2-14.el9_6.1
fixed
python3-ipaclient
RHEL 9
0:4.12.2-14.el9_6.1
fixed
python3-ipalib
RHEL 9
0:4.12.2-14.el9_6.1
fixed
python3-ipaserver
RHEL 9
0:4.12.2-14.el9_6.1
fixed
python3-ipatests
RHEL 9
0:4.12.2-14.el9_6.1
fixed