Skip to content
COOEY

EXPOSURES › CVE-2017-7494

CVE-2017-7494

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-03-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-7494 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Samba's CVE-2017-7494 allowed attackers to upload and execute arbitrary code on vulnerable servers via writable shares.

This remote code execution flaw let malicious actors upload shared libraries to writable Samba shares and force the server to load and execute them. DIB organizations must ensure Samba is patched and shares are restricted to prevent exploitation. The vulnerability was actively exploited in the wild and linked to ransomware campaigns.

Shame score — A critical RCE flaw in widely deployed Samba was actively exploited in the wild and linked to ransomware, indicating severe negligence in patching and secure configuration.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.