peter bassill · operator
$ cve CVE-2025-10230 JSON

CVE-2025-10230

10.0
CRITICAL · CVSS 3.1 · EPSS 39.7% (pctl 99)

Patch early

EPSS 39.7% — above the 10% action threshold.

Description

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS39.65% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2025-11-07
Last modified2026-08-31

References

→ the Explorer  ·  watch your stack  ·  NVD