CVE-2019-10197 is a critical directory traversal vulnerability in Samba versions 4.9.x through 4.9.13, 4.10.x through 4.10.8, and 4.11.x through 4.11.0rc3, affecting various Linux distributions. An unauthenticated attacker can exploit this flaw to escape shared directories and access arbitrary files outside the intended share. With a CVSS score of 9.1 (CRITICAL), this vulnerability allows for high confidentiality and integrity impact without requiring user interaction or complex attack vectors. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating awareness. Despite its age, it is not listed in the KEV catalog and its EPSS score is low, suggesting limited observed exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.9.0, <= 4.9.13CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.10.0, <= 4.10.8CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
4.9.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.9.0:rc1:*:*:*:*:*:* | ||
4.9.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.9.0:rc2:*:*:*:*:*:* | ||
4.9.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:4.9.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.