CVE-2017-7494
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Samba Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-94
מוצרים מושפעים
samba: samba; debian: debian linux
קישורים
- https://www.samba.org/samba/security/CVE-2017-7494.html PatchVendor Advisory
- https://www.samba.org/samba/security/CVE-2017-7494.html PatchVendor Advisory
- http://www.debian.org/security/2017/dsa-3860 Third Party Advisory
- http://www.securityfocus.com/bid/98636 Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038552 Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1270 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1271 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1272 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1273 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1390 Third Party Advisory