Vulnerability record · CVE-2003-0085 · published 31 March 2003
CVE-2003-0085: Samba smbd SMB/CIFS fragment reassembly buffer overflow
Samba · Samba
Samba's smbd daemon contains a buffer overflow in the SMB/CIFS packet fragment re-assembly code. A remote attacker can send crafted fragmented SMB packets to overwrite memory and execute arbitrary code. The flaw affects Samba before 2.2.8 and Samba-TNG before 0.3.1.
Description
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus very high EPSS, makes this a critical risk for unpatched Samba servers.
What it is
Samba's smbd daemon contains a buffer overflow in the SMB/CIFS packet fragment re-assembly code. A remote attacker can send crafted fragmented SMB packets to overwrite memory and execute arbitrary code. The flaw affects Samba before 2.2.8 and Samba-TNG before 0.3.1.
Impact
Successful exploitation gives the attacker remote code execution with the privileges of the smbd process, typically root on the host. This can lead to full system compromise and further lateral movement.
Attack surface
The vulnerability is reachable over the network via SMB/CIFS on TCP port 445 or 139. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/Au:N.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is very high at 0.879 (99.8th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade Samba to version 2.2.8 or later, or Samba-TNG to 0.3.1 or later, as applicable.
- Apply vendor patches from Red Hat, Debian, Gentoo, Mandriva, Novell, or SGI advisories referenced in the record.
- Restrict network access to SMB/CIFS ports (139/tcp, 445/tcp) to trusted hosts only.
- Run smbd with minimal privileges where possible and monitor for unexpected process behavior.
Detection
- Monitor SMB traffic for malformed or unusually fragmented SMB/CIFS packets.
- Inspect smbd logs and system logs for crashes, restarts, or abnormal child process creation.
- Use network IDS signatures for SMB fragment reassembly overflow attempts if available.
- Track host-based indicators such as unexpected outbound connections from SMB servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0085 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.