Samba是Samba开源的一个适用于 Linux 和 Unix 的标准 Windows 互操作性程序套件。 Samba存在操作系统命令注入漏洞,该漏洞源于前端WINS钩子处理中对NetBIOS名称未进行适当验证或转义,可能导致远程命令执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| None | None | < 4.21.9 |
affected |
4.22.0< 4.21.5 |
affected | ||
4.23.0< 4.23.2 |
affected | ||
| Red Hat | Red Hat Enterprise Linux 10 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
unaffected |
any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 4.21.9 | - |
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PoC for CVE-2025-10230 - Samba WINS hook command injection | https://github.com/dptsec/CVE-2025-10230 | POC Details |
| 2 | CVE-2025-10230 | https://github.com/B1ack4sh/Blackash-CVE-2025-10230 | POC Details |
| 3 | CVE-2025-10230 PoC - Samba WINS Hook Command Injection | https://github.com/nehkark/CVE-2025-10230 | POC Details |
| 4 | OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0 | https://github.com/marcostolosa/CVE-2025-10230 | POC Details |
| 5 | CVE-2025-10230 | https://github.com/Ashwesker/Blackash-CVE-2025-10230 | POC Details |
| 6 | CVE-2025-10230 | https://github.com/Ashwesker/Ashwesker-CVE-2025-10230 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet