KEVIntel
9.8
CVSS
Critical

CVE-2017-7494

PUBLISHED

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Samba
Product
samba
Published
May 30, 2017
EPSS

Description

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

windows cisa malware ransomware metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2023-03-30 00:00:00 UTC · Source

Used in malware

Recorded 2023-03-30 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 30, 2023

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

is_known_pipename

metasploit · Created Unknown

Metasploit module for CVE-2017-7494

d3fudd/CVE-2017-7494_SambaCry

github · Created 2022-11-01 23:17:25 UTC · 5 stars

SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit

00mjk/exploit-CVE-2017-7494

github · Created 2022-05-29 16:27:13 UTC · 1 stars

SambaCry exploit (CVE-2017-7494)

adjaliya/-CVE-2017-7494-Samba-Exploit-POC

github · Created 2021-09-29 20:31:20 UTC · 0 stars

According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable Samba versions, for which there is no fix. The newest Samba models, including the models 4.6.x before 4.6.4, 4.5.x before 4.5.10 and 3.5.0 before 4.4.13, was impacted by this error. May 24, 2017, Samba released version 4.6.4, which fixes a serious remote code execution vulnerability, vulnerability number CVE-2017-7494, which affected Samba 3.5.0 onwards. Vulnerability number: CVE-2017-7494 Severity Rating: High Affected software: • Samba Version < 4.6.4 • Samba Version < 4.5.10 • Samba Version < 4.4.14 Unaffected software: • Samba Version = 4.6.4 • Samba Version = 4.5.10 • Samba Version = 4.4.14

0xm4ud/noSAMBAnoCRY-CVE-2017-7494

github · Created 2021-05-09 02:32:54 UTC · 4 stars

CVE-2017-7494 python exploit

Hansindu-M/CVE-2017-7494_IT19115344

github · Created 2020-05-10 21:17:55 UTC · 0 stars

A remote code execution flaw was found in Samba. A malicious authenticated samba client, having write access to the samba share, could use this flaw to execute arbitrary code as root.

incredible1yu/CVE-2017-7494

github · Created 2018-05-10 08:12:31 UTC · 0 stars

CVE-2017-7494 C poc

Zer0d0y/Samba-CVE-2017-7494

github · Created 2017-07-28 06:21:29 UTC · 1 stars

搭建漏洞利用测试环境

joxeankoret/CVE-2017-7494

github · Created 2017-06-05 16:25:57 UTC · 257 stars

Remote root exploit for the SAMBA CVE-2017-7494 vulnerability

opsxcq/exploit-CVE-2017-7494

github · Created 2017-05-26 00:58:25 UTC · 381 stars

SambaCry exploit and vulnerable container (CVE-2017-7494)

homjxi0e/CVE-2017-7494

github · Created 2017-05-25 14:13:10 UTC · 0 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit