Executive brief
Samba is vulnerable to remote code execution when a malicious client uploads a shared library to a writable share. The server can then be coerced into loading and executing the library, allowing for full system compromise.
Affected products
- Samba Samba since 3.5.0 before 4.6.4, 4.5.10, and 4.4.14
Timeline
- 2017-05-24: disclosed: Samba security advisory published
- 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog