CVE-2025-10230
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 39.7% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Deferred
- Published
- 2025-11-07
Workaround
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
CVE-2025-10230 at NVD
5 known exploits for CVE-2025-10230
Proof-of-concept code and exploit modules indexed by Sploitus