Junglewise Threat Intelligence

CVE-2025-10230: Samba command injection in WINS hook handling

CVE-2025-10230 · Severity: critical · CVSS 10 · Published 2025-11-07

Technologies: Samba. Vendors: Samba.

Executive brief

Samba, a widely used software for sharing files and managing network identities, contains a critical security flaw in its WINS server component. An unauthenticated attacker can send specially crafted network packets to take complete control of the server. This could lead to the theft of sensitive company data, disruption of network services, or a total takeover of the organization's domain controller.

Technical details

An OS command injection vulnerability (CWE-78) exists in Samba's front-end WINS hook handling. The root cause is the failure to properly validate or escape NetBIOS names received from registration packets before passing them to a shell command via the 'wins hook'. An unauthenticated network attacker can exploit this by sending malicious WINS registration packets containing shell metacharacters. Successful exploitation results in remote command execution (RCE) with the privileges of the Samba process, typically on an Active Directory Domain Controller. The vulnerability is addressed in Samba versions 4.21.9, 4.21.5 (for the 4.22 branch), and 4.23.2.

Affected products

  • Samba Samba < 4.21.9, 4.22.0 < 4.21.5, 4.23.0 < 4.23.2

Timeline

  • 2025-09-10: disclosed: Initial report in Red Hat Bugzilla
  • 2025-11-07: advisory: NVD publication date

References

Related threats