CVE-2019-14902: Medium severity Samba Samba vulnerability
Last updated 18 August 2025
Other sources
There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-14902.
What is the severity of CVE-2019-14902?
The severity of CVE-2019-14902 is medium with a CVSS score of 5.4.
Which versions of Samba are affected by CVE-2019-14902?
All Samba 4.11.x versions before 4.11.5, all Samba 4.10.x versions before 4.10.12, and all Samba 4.9.x versions before 4.9.18 are affected.
How can I fix CVE-2019-14902?
To fix CVE-2019-14902, update to Samba version 4.11.5 or later for Samba 4.11.x, version 4.10.12 or later for Samba 4.10.x, and version 4.9.18 or later for Samba 4.9.x.
Where can I find more information about CVE-2019-14902?
You can find more information about CVE-2019-14902 at the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14902), [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20200122-0001/), [Synology Security Advisory](https://www.synology.com/security/advisory/Synology_SA_20_01).