Does CVE-2022-38023 affect local authentication for CIFS users
Applies to
- ONTAP 9
Answer
- CVE-2022-38023 is only for RPC_NETLOGON, not specifically for NTLM.
- RPC_NETLOGON is only used when communicating to Active Directory Domain Controllers
- CVE-2022-38023 does not impact local authenticated CIFS users
Additional Information
How to diagnose and mitigate impact due to CVE-2022-38023 - Resolution Guide - NetApp Knowledge Base
- To ensure that local accounts are being evaluated, the client has to pass credentials as "cifsservername\local-user".
- Here's an example of a new use using that format: net use z: \\IP_SVM\share1 /user:cifsservername\local-user"
- If the credentials are not passed as "cifsservername\local-user", ONTAP will attempt to use passthrough and refer those credentials to the local DC