CVE-2017-7494: SambaCry
A remote code execution vulnerability in Samba caused by insufficient validation of client-supplied paths, letting a client that can write to any share upload a shared library and then trigger the server to load and execute it, achieving code execution with the privileges of the Samba server process, often root.
View the authoritative record on NVD ↗Affected software
- Samba 3.5.0 through 4.6.4, 4.5.10, and 4.4.14
How it's exploited
Upload a malicious shared library file to any Samba share the attacker can write to, then use an RPC call to make smbd load that shared library from the known share path, executing attacker-controlled code with the privileges of the Samba server process.
Severity
CVE-2017-7494 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2017-7494 is categorized under CWE-94, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this (white-box)
This weakness (Code Injection) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 6 rules for it, flagging the issue directly in your source code as part of the pentest.
Remediation
Upgrade to Samba 4.6.4, 4.5.10, or 4.4.14 or later, or apply the interim workaround of adding "nt pipe support = no" to the [global] section of smb.conf and restarting the smbd daemon.
Frequently asked questions
What is CVE-2017-7494?
A remote code execution vulnerability in Samba caused by insufficient validation of client-supplied paths, letting a client that can write to any share upload a shared library and then trigger the server to load and execute it, achieving code execution with the privileges of the Samba server process, often root.
How severe is CVE-2017-7494?
CVE-2017-7494 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2017-7494?
CVE-2017-7494 affects Samba 3.5.0 through 4.6.4, 4.5.10, and 4.4.14.
How do you fix CVE-2017-7494?
Upgrade to Samba 4.6.4, 4.5.10, or 4.4.14 or later, or apply the interim workaround of adding "nt pipe support = no" to the [global] section of smb.conf and restarting the smbd daemon.
Where is the authoritative record for CVE-2017-7494?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2017-7494 at https://nvd.nist.gov/vuln/detail/CVE-2017-7494, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest