SambaCry! Samba CVE-2017-7494 Remote Code Execution Vulnerability
by CIRT Team
Description: All versions of Samba from 3.5.0 onward are vulnerable to a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
Impact: Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application. Failed exploits will result in denial-of-service conditions.
Mitigation: Security patch is available in Samba official site.
Reference URL’s:
- https://www.samba.org/samba/security/CVE-2017-7494.html
- https://www.samba.org/samba/history/security.html
- http://www.securityfocus.com/bid/98636/discuss
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts