CVE-2019-14902 PUBLISHED

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

EPSS 3.50% · 87.5th percentile

Risk Scores

EPSS Score
3.50%
87.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSsamba2:4.7.6+dfsg~ubuntu-0ubuntu2.2, 2:4.7.6+dfsg~ubuntu-0ubuntu2.4, 2:4.7.6+dfsg~ubuntu-0ubuntu2.5
Ubuntu:Pro:14.04:LTSsamba2:4.3.11+dfsg-0ubuntu0.14.04.13, 2:4.3.11+dfsg-0ubuntu0.14.04.14, 2:4.3.11+dfsg-0ubuntu0.14.04.16
Ubuntu:Pro:16.04:LTSsamba2:4.3.11+dfsg-0ubuntu0.16.04.30, 0, 2:4.1.17+dfsg-4ubuntu2
Ubuntu:20.04:LTSsamba0, 2:4.10.7+dfsg-0ubuntu2, 2:4.10.7+dfsg-0ubuntu3

Timeline

References

Open in Interactive Console →