CVE-2019-14870 is a medium-severity vulnerability affecting Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11, and 4.11.x before 4.11.3, specifically within its Active Directory Domain Controller (AD DC) implementation. The flaw allows the Samba AD DC to incorrectly set the forwardable flag for Kerberos tickets during S4U2Self delegation, even when the impersonated client has the "not-delegated" attribute set, which should prevent ticket forwarding. This could lead to unauthorized delegation of client credentials. The vulnerability has a CVSS v3.1 score of 5.4 (Medium), indicating a low-complexity attack that can be executed over the network with low privileges, potentially leading to limited confidentiality and integrity impacts. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. Given the lack of active exploitation and public exploit availability, the immediate risk is moderate. However, organizations using affected Samba versions should prioritize patching to mitigate the potential for unauthorized credential delegation within their Active Directory environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.9.17CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.10.0, < 4.10.11CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.11.0, < 4.11.3CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.