Executive brief
Samba, a widely used software for sharing files and managing network identities, contains a critical security flaw in its WINS server component. An unauthenticated attacker can send specially crafted network packets to take complete control of the server. This could lead to the theft of sensitive company data, disruption of network services, or a total takeover of the organization's domain controller.
Technical details
An OS command injection vulnerability (CWE-78) exists in Samba's front-end WINS hook handling. The root cause is the failure to properly validate or escape NetBIOS names received from registration packets before passing them to a shell command via the 'wins hook'. An unauthenticated network attacker can exploit this by sending malicious WINS registration packets containing shell metacharacters. Successful exploitation results in remote command execution (RCE) with the privileges of the Samba process, typically on an Active Directory Domain Controller. The vulnerability is addressed in Samba versions 4.21.9, 4.21.5 (for the 4.22 branch), and 4.23.2.
Affected products
- Samba Samba < 4.21.9, 4.22.0 < 4.21.5, 4.23.0 < 4.23.2
Timeline
- 2025-09-10: disclosed: Initial report in Red Hat Bugzilla
- 2025-11-07: advisory: NVD publication date
References
- https://www.samba.org/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/security/cve/CVE-2025-10230
- https://bugzilla.redhat.com/show_bug.cgi?id=2394377
- https://www.samba.org/samba/history/security.html
- https://www.vicarius.io/vsociety/posts/cve-2025-10230-detect-samba-vulnerability
- https://www.vicarius.io/vsociety/posts/cve-2025-10230-mitigate-samba-vulnerability