cbcvebase.
CVE-2019-10197
published 2019-09-03

CVE-2019-10197: A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the…

PriorityP357critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
3.18%
86.7th percentile
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debiansamba< samba 2:4.9.13+dfsg-1 (bookworm)samba 2:4.9.13+dfsg-1 (bookworm)
sambasamba
sambasamba
sambasamba
sambasamba
sambasamba
sambasamba
sambasamba>= 0 < 2:4.9.13+dfsg-12:4.9.13+dfsg-1
sambasamba>= 0 < 2:4.9.13+dfsg-12:4.9.13+dfsg-1
sambasamba>= 0 < 2:4.9.13+dfsg-12:4.9.13+dfsg-1
sambasamba>= 0 < 2:4.9.13+dfsg-12:4.9.13+dfsg-1
sambasamba4.10.0 – 4.10.8
sambasamba4.9.0 – 4.9.13

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.