CVE-2019-3870
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2019-3870 is a vulnerability affecting Samba versions 4.9 and earlier, as well as 4.10.2. During the creation of a new Active Directory Domain Controller (AD DC), Samba inadvertently creates a directory with potentially insecure permissions. In some instances, this directory may have group writable permissions (0755), which is a departure from the default owner-only access (0700) since Samba 4.8. Within the affected directory, critical files like krb5.conf and servicePrincipalName values are created with world-writable permissions (0666). This issue could potentially lead to unauthorized modification or access to these sensitive files.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Samba
- DiskStation Manager
- Fedora Operating System
- Synology Router Manager
Affected Vendors
- Samba Financial Group
- Fedora Project
- Synology