samba: Loading shared modules from any path in the system leading to RCE (SambaCry)
Published May 30, 2017 ·Due Apr 20, 2023
9.8
CRITICALCVSS 3.1
EPSS 99.45%
Description
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
Affected products
-
- Version since 3.5.0StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 5 Extended Lifecycle Support
samba3x-0:3.6.23-14.el5_11
Fixed · RHSA-2017:1272
Red Hat Enterprise Linux 6
samba-0:3.6.23-43.el6_9
Fixed · RHSA-2017:1270
Red Hat Enterprise Linux 6
samba4-0:4.2.10-10.el6_9
Fixed · RHSA-2017:1271
Red Hat Enterprise Linux 6.2 Advanced Update Support
samba-0:3.6.23-32.el6_2
Fixed · RHSA-2017:1390
Red Hat Enterprise Linux 6.4 Advanced Update Support
samba-0:3.6.23-32.el6_4
Fixed · RHSA-2017:1390
Red Hat Enterprise Linux 6.5 Advanced Update Support
samba-0:3.6.23-32.el6_5
Fixed · RHSA-2017:1390
Red Hat Enterprise Linux 6.5 Telco Extended Update Support
samba-0:3.6.23-32.el6_5
Fixed · RHSA-2017:1390
Red Hat Enterprise Linux 6.6 Advanced Update Support
samba-0:3.6.23-32.el6_6
Fixed · RHSA-2017:1390
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
samba-0:3.6.23-32.el6_6
Fixed · RHSA-2017:1390
Red Hat Enterprise Linux 6.7 Extended Update Support
samba-0:3.6.23-32.el6_7
Fixed · RHSA-2017:1390
Red Hat Enterprise Linux 7
samba-0:4.4.4-14.el7_3
Fixed · RHSA-2017:1270
Red Hat Enterprise Linux 7.2 Extended Update Support
samba-0:4.2.10-11.el7_2
Fixed · RHSA-2017:1390
Red Hat Gluster Storage 3.2 for RHEL 6
samba-0:4.4.6-5.el6rhs
Fixed · RHSA-2017:1273
Red Hat Gluster Storage 3.2 for RHEL 7
samba-0:4.4.6-5.el7rhgs
Fixed · RHSA-2017:1273
Red Hat Enterprise Linux 5
samba
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | samba3x-0:3.6.23-14.el5_11 | Fixed | RHSA-2017:1272 |
| Red Hat Enterprise Linux 6 | samba-0:3.6.23-43.el6_9 | Fixed | RHSA-2017:1270 |
| Red Hat Enterprise Linux 6 | samba4-0:4.2.10-10.el6_9 | Fixed | RHSA-2017:1271 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | samba-0:3.6.23-32.el6_2 | Fixed | RHSA-2017:1390 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | samba-0:3.6.23-32.el6_4 | Fixed | RHSA-2017:1390 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | samba-0:3.6.23-32.el6_5 | Fixed | RHSA-2017:1390 |
| Red Hat Enterprise Linux 6.5 Telco Extended Update Support | samba-0:3.6.23-32.el6_5 | Fixed | RHSA-2017:1390 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | samba-0:3.6.23-32.el6_6 | Fixed | RHSA-2017:1390 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | samba-0:3.6.23-32.el6_6 | Fixed | RHSA-2017:1390 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | samba-0:3.6.23-32.el6_7 | Fixed | RHSA-2017:1390 |
| Red Hat Enterprise Linux 7 | samba-0:4.4.4-14.el7_3 | Fixed | RHSA-2017:1270 |
| Red Hat Enterprise Linux 7.2 Extended Update Support | samba-0:4.2.10-11.el7_2 | Fixed | RHSA-2017:1390 |
| Red Hat Gluster Storage 3.2 for RHEL 6 | samba-0:4.4.6-5.el6rhs | Fixed | RHSA-2017:1273 |
| Red Hat Gluster Storage 3.2 for RHEL 7 | samba-0:4.4.6-5.el7rhgs | Fixed | RHSA-2017:1273 |
| Red Hat Enterprise Linux 5 | samba | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability exists in the samba server, client side packages are not affected.
Red Hat mitigation
Any of the following: 1. SELinux is enabled by default and our default policy prevents loading of modules from outside of samba's module directories and therefore blocks the exploit 2. Mount the filesystem which is used by samba for its writable share using "noexec" option. 3. Add the parameter: nt pipe support = no to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing any named pipe endpoints. Note this can disable some expected functionality for Windows clients.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Mar 30, 2023
Patch Due
Apr 20, 2023
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 99.45% (0.99448) | 99.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 99.45% (0.99448) | 99.94th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.30% (0.94296) | 99.93th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.16% (0.97155) | 99.85th | v3 (v2023.03.01) |
| Sep 3, 2023 | 97.26% (0.97264) | 99.77th | v3 (v2023.03.01) |
| Jul 26, 2023 | 97.28% (0.97281) | 99.77th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.36% (0.97363) | 99.83th | v3 (v2023.03.01) |
| May 10, 2023 | 97.22% (0.97224) | 99.71th | v3 (v2023.03.01) |
| May 8, 2023 | 97.18% (0.97181) | 99.67th | v3 (v2023.03.01) |
| Apr 9, 2023 | 97.40% (0.97402) | 99.85th | v3 (v2023.03.01) |
| Mar 31, 2023 | 97.37% (0.97372) | 99.81th | v3 (v2023.03.01) |
| Mar 15, 2023 | 97.39% (0.97387) | 99.82th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.40% (0.97396) | 99.82th | v3 (v2023.03.01) |
| Mar 6, 2023 | 95.65% (0.95647) | 99.98th | v2 (v2022.01.01) |
| Feb 13, 2023 | 95.65% (0.95647) | 99.98th | v2 (v2022.01.01) |
| Feb 3, 2023 | 94.95% (0.94954) | 99.96th | v2 (v2022.01.01) |
| Feb 4, 2022 | 95.65% (0.95647) | 99.98th | v2 (v2022.01.01) |
| Feb 3, 2022 | 72.61% (0.72611) | 99.69th | v1 |
| Sep 1, 2021 | 72.61% (0.72611) | 99.85th | v1 |
| Apr 14, 2021 | 72.61% (0.72611) | 0.00th | v1 |
References (22)
- http://www.debian.org/security/2017/dsa-3860 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/98636 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038552 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1270 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1271 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1272 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1273 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1390 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-7494 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1450347 Issue Tracking
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2018-095-01+Security+Notification+Umotion+V1.1.pdf&p_Doc_Ref=SEVD-2018-095-01 x_refsource_MISCThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us x_refsource_CONFIRMThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03759en_us x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-7494
- https://security.gentoo.org/glsa/201805-07 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20170524-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-7494 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2017-7494
- https://www.exploit-db.com/exploits/42060/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42084/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.samba.org/samba/security/CVE-2017-7494.html x_refsource_CONFIRMPatchVendor Advisory
Change history (0)
No recorded changes yet.