CVE-2019-14847
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.9epss 2.4%
exploitation probability
2.4%top 18% of all CVEs
observed exploitation
nono source reports it
A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected products
Samba · sambaReferences
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00015.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14847https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OKPYHDFI7HRELVXBE5J4MTGSI35AKFBI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XQ3IUACPZJXSC4OM6P2V4IC4QMZQZWPD/https://www.samba.org/samba/security/CVE-2019-14847.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_35