CVE-2019-12435 is a NULL pointer dereference vulnerability in Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5, specifically affecting the AD DC DNS management server RPC process. This flaw can lead to a Denial of Service (DoS) with a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity by a low-privileged attacker. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion and media coverage, including an article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.9.0, < 4.9.9CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.10.0, < 4.10.5CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.