Back

CRITICAL KEV Used in ransomware campaigns

samba: Loading shared modules from any path in the system leading to RCE (SambaCry)

Published May 30, 2017 ·Due Apr 20, 2023

Description

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

Affected products

Remediation

Red Hat statement

This vulnerability exists in the samba server, client side packages are not affected.

Red Hat mitigation

Any of the following: 1. SELinux is enabled by default and our default policy prevents loading of modules from outside of samba's module directories and therefore blocks the exploit 2. Mount the filesystem which is used by samba for its writable share using "noexec" option. 3. Add the parameter: nt pipe support = no to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing any named pipe endpoints. Note this can disable some expected functionality for Windows clients.

Metrics

Weaknesses (1)

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 30, 2017
Updated Oct 21, 2025
Reserved Apr 5, 2017
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 24, 2017