CVE-2019-9579

HIGH

Illumos <5.1.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

References (2)

Core 2
Core References
Mitigation, Patch, Vendor Advisory
https://www.illumos.org/issues/10506

Scores

CVSS v3 8.1
EPSS 0.0050
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (2)
illumos/illumos
oracle/solaris 11
Published Dec 26, 2022
Tracked Since Feb 18, 2026