CVE-2019-9579 - CVE House
Back to Database
Status published Unknown CVE-2019-9579

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5...

Vulnerability Description

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-9579

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

illumos, solaris
Vulnerable Versions:
11

Timeline

Official Publish: December 26th, 2022
Last Modified: April 14th, 2025
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.