A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-10663.json"