Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-3870

22
FAUCET Score

CVE-2019-3870 is a medium-severity vulnerability affecting Samba versions 4.9 through 4.9.5 and 4.10.0 through 4.10.1, as well as products like fedoraproject and Synology. It arises from world-writable files (e.g., krb5.conf) being created in a potentially world-readable private directory during Samba AD DC setup or upgrade, allowing local attackers to modify these files. With a CVSS score of 6.1, this vulnerability has low attack complexity and requires local user privileges, potentially leading to high impact on availability and low impact on integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.9.0, < 4.9.6CPE matchmatch criteria
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
>= 4.10.0, < 4.10.2CPE matchmatch criteria
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
29CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:synology:directory_server:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.1MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
4.2
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 93rd percentile among its peer group of 15,937 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

microsoftpatch availablevia msrc
Product: 16864-16817Fixed in: 4.18.3-1
microsoftpatch availablevia msrc
Product: 16864-17084Fixed in: 4.18.3-1
microsoftpatch availablevia msrc
Product: azl3 samba 4.18.3-1 on Azure Linux 3.0Fixed in: 4.18.3-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 4.18.3-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 4.18.3-1

Vendor Advisories (3)

microsoft2024-Oct/CVE-2019-3870

CVE-2019-3870

Oct 8, 2024
microsoft2019-Apr/CVE-2019-3870Moderate

A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC files are created in a private subdirectory of the install location. This directory is typically mode 0700 that is owner (root) only access. However in some upgraded installations it will have other permissions such as 0755 because this was the default before Samba 4.8. Within this directory files are created with mode 0666 which is world-writable including a sample krb5.conf and the list of DNS names and servicePrincipalName values to update.

Apr 9, 2019
redhatCVE-2019-3870Moderate

samba: World writable files in Samba AD DC private/ dir

Apr 9, 2019

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
bugzilla.samba.org / show_bug.cgi
ExploitIssue TrackingPatchVendor Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6354GALK73CZWQKFUG7AWB6EIEGFMF62
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/JTJVFA3RZ6G2IZDTVKLHRMX6QBYA4GPA
support.f5.com / csp/article/K20804356
Third Party Advisory
samba.org / samba/security/CVE-2019-3870.html
MitigationPatchVendor Advisory
synology.com / security/advisory/Synology_SA_19_15
Third Party Advisory