CVE-2004-0186 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 1.6% (pctl 75)
Patch early
A public exploit exists.
Description
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 1.6% — more likely to be exploited than 75% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-03-15 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| linux | linux kernel |
| samba | samba |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Samba 2.2.8 (Linux Kernel 2.6 / Debian / Mandrake) - Share Privilege Escalation | 2004-02-09 |
References
- http://marc.info/?l=bugtraq&m=107636290906296&w=2
- http://marc.info/?l=bugtraq&m=107657505718743&w=2
- http://www.debian.org/security/2004/dsa-463
- http://www.osvdb.org/3916
- http://www.securityfocus.com/bid/9619
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15131
- http://marc.info/?l=bugtraq&m=107636290906296&w=2
- http://marc.info/?l=bugtraq&m=107657505718743&w=2
- http://www.debian.org/security/2004/dsa-463
- http://www.osvdb.org/3916
- http://www.securityfocus.com/bid/9619
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15131
→ the Explorer · watch your stack · NVD