Junglewise Threat Intelligence

CVE-2017-7494: Samba Remote Code Execution Vulnerability

CVE-2017-7494 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-03-30

Technologies: Samba. Vendors: Samba.

Executive brief

Samba is vulnerable to remote code execution when a malicious client uploads a shared library to a writable share. The server can then be coerced into loading and executing the library, allowing for full system compromise.

Affected products

  • Samba Samba since 3.5.0 before 4.6.4, 4.5.10, and 4.4.14

Timeline

  • 2017-05-24: disclosed: Samba security advisory published
  • 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats