{"id":7716,"date":"2025-10-16T10:04:00","date_gmt":"2025-10-16T10:04:00","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/16\/critical-samba-rce-vulnerability-enables-arbitrary-code-execution\/"},"modified":"2025-10-16T10:04:00","modified_gmt":"2025-10-16T10:04:00","slug":"critical-samba-rce-vulnerability-enables-arbitrary-code-execution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/16\/critical-samba-rce-vulnerability-enables-arbitrary-code-execution\/","title":{"rendered":"Critical Samba RCE Vulnerability Enables Arbitrary Code Execution"},"content":{"rendered":"<p>    Critical Samba RCE Vulnerability Enables Arbitrary Code Execution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Samba has disclosed a severe remote code execution (RCE) flaw that could allow attackers to hijack <a href=\"https:\/\/cybersecuritynews.com\/active-directory-misconfigurations\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory domain controllers<\/a>.<\/p>\n<p>Tracked as CVE-2025-10230, the vulnerability stems from improper validation in the Windows Internet Name Service (WINS) hook mechanism, earning a perfect CVSS 3.1 score of 10.0 for its ease of exploitation and devastating potential impact.<\/p>\n<p>Samba, the open-source implementation of the SMB\/CIFS networking protocol widely used in Linux and Unix environments to mimic Windows file sharing and authentication, has long been a cornerstone for cross-platform enterprise networks. <\/p>\n<p>However, this flaw exposes organizations relying on it as an <a href=\"https:\/\/cybersecuritynews.com\/active-directory-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory Domain<\/a> Controller (AD DC) to unauthenticated attacks.<\/p>\n<p>Discovered by security researcher Igor Morgenstern of Aisle Research, the issue affects all Samba versions since 4.0 when specific configurations are enabled, namely, WINS support and a custom \u2018wins hook\u2019 script in the smb.conf file.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-samba-rce-vulnerability\"><strong>Samba RCE Vulnerability<\/strong><\/h2>\n<p>WINS, a deprecated Microsoft protocol from the pre-DNS era, resolves NetBIOS names in legacy Windows networks. <\/p>\n<p>By default, WINS support is disabled in Samba, but when activated on an AD DC alongside the \u2018wins hook\u2019 parameter, which triggers an external script on name changes, the system becomes a sitting duck.<\/p>\n<p>Attackers can send crafted WINS name registration requests containing shell metacharacters within the 15-character NetBIOS limit. <\/p>\n<p>These inject arbitrary commands into the hook script, executed via a shell without any <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> or user interaction required.<\/p>\n<p>The vulnerability\u2019s scope is narrow but perilous: it only impacts Samba in AD DC mode (roles like \u2018domain controller\u2019 or \u2018active directory domain controller\u2019). <\/p>\n<p>Standalone or member servers, which use a different WINS implementation, remain unaffected. In practice, this could let remote threat actors on the network pivot to full system compromise, exfiltrating sensitive data, deploying ransomware, or escalating privileges in hybrid Windows-Linux setups common in enterprises.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-mitigations\"><strong>Mitigations<\/strong><\/h2>\n<p>Samba maintainers <a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2025-10230.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">acted swiftly<\/a>, releasing patches to their security portal and issuing updated versions: 4.23.2, 4.22.5, and 4.21.9.<\/p>\n<p>Administrators should prioritize upgrades, especially in environments with legacy WINS dependencies. <\/p>\n<p>As a workaround, disable the \u2018wins hook\u2019 parameter entirely or set \u2018wins support = no\u2019 in smb.conf Samba\u2019s default configuration already avoids this risky combo, making most setups safe out of the box.<\/p>\n<p>Experts urge a broader review: WINS is obsolete, and its use on modern domain controllers is rare and inadvisable. Even post-patch, admins might disable hooks altogether, as future Samba releases could drop support. <\/p>\n<p>With attack surfaces expanding in hybrid clouds, this incident underscores the need to audit and phase out antiquated protocols before they become entry points for nation-state actors or cybercriminals.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/critical-samba-rce-vulnerability\/\">Critical Samba RCE Vulnerability Enables Arbitrary Code Execution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/critical-samba-rce-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Samba RCE Vulnerability Enables Arbitrary Code Execution Samba has disclosed a severe remote code execution (RCE) flaw that could allow attackers to hijack Active Directory domain controllers. Tracked as CVE-2025-10230, the vulnerability stems from improper validation in the Windows Internet Name Service (WINS) hook mechanism, earning a perfect CVSS 3.1 score of 10.0 for [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-7716","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7716"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7716"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7716\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}