UBUNTU-CVE-2025-10230
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-10230
UBUNTU-CVE-2025-10230
Summary:
Details: A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.
References: https://ubuntu.com/security/CVE-2025-10230, https://www.cve.org/CVERecord?id=CVE-2025-10230, https://ubuntu.com/security/notices/USN-7826-1, https://ubuntu.com/security/notices/USN-7826-2
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.14.04.20+esm15?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
