PT-2025-42432 · Samba+6 · Samba+6
CVE-2025-10230
·
Published
2025-01-01
·
Updated
2026-06-25
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samba versions 4.0 through 4.21.8
Samba versions 4.22.0 through 4.22.4
Samba versions 4.23.0 through 4.23.1
Description
A command injection flaw exists in the front-end WINS hook handling of Samba Active Directory Domain Controllers. When the WINS server feature is enabled and a
wins hook parameter is configured, NetBIOS names from registration packets are passed to a shell without proper validation or escaping. An unauthenticated network attacker can send a specially crafted WINS registration packet to UDP port 137 containing shell metacharacters in the NetBIOS name, allowing them to achieve remote command execution with the privileges of the Samba process. This issue specifically affects servers acting as Active Directory Domain Controllers; member or standalone servers are not affected.Recommendations
Update to version 4.21.9.
Update to version 4.22.5.
Update to version 4.23.2.
As a temporary workaround, disable WINS by setting
wins support = no in the configuration.
As a temporary workaround, remove the wins hook parameter from the configuration.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Red Os
Samba
Suse
Ubuntu