← Vulnerability feed

Vulnerability record · CVE-2007-2446 · published 14 May 2007

CVE-2007-2446: Samba smbd NDR parsing heap buffer overflows allow remote code execution

Samba · Samba

Samba 3.0.0 through 3.0.25rc3 contains multiple heap-based buffer overflows in the NDR parsing code of smbd, reachable through crafted MS-RPC requests. The affected parsing routines include DFSEnum, RFNPCNEX, LsarAddPrivilegesToAccount, NetSetFileSecurity, and LsarLookupSids/LsarLookupSids2. Because these are memory corruption flaws in a network-facing service, they matter for any environment exposing SMB/RPC services.

10.0 CVSS 2.0 High EPSS 78% · top 0.4% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
150References
16 Jun 2026Last modified by NVD

Description

Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with no authentication or interaction required, combined with a very high EPSS score, makes this a top-priority remote code execution risk for exposed Samba services.

What it is

Samba 3.0.0 through 3.0.25rc3 contains multiple heap-based buffer overflows in the NDR parsing code of smbd, reachable through crafted MS-RPC requests. The affected parsing routines include DFSEnum, RFNPCNEX, LsarAddPrivilegesToAccount, NetSetFileSecurity, and LsarLookupSids/LsarLookupSids2. Because these are memory corruption flaws in a network-facing service, they matter for any environment exposing SMB/RPC services.

Impact

A remote attacker can execute arbitrary code in the context of the smbd process, which typically runs with elevated privileges on the host. Successful exploitation can lead to full compromise of the file server and any data or credentials it handles.

Attack surface

The flaw is reached over the network via crafted MS-RPC requests to smbd; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing the Samba SMB/RPC service is potentially reachable.

Exploitation

The record does not list this CVE in CISA KEV and documents no ransomware use, but EPSS is very high (0.773 probability, 99.5th percentile), indicating strong likelihood of exploitation activity. Reference tags are vendor advisories only, so no public exploit code is confirmed by this record.

What to do

  • Upgrade Samba to a version later than 3.0.25rc3 that contains the NDR parsing fixes.
  • If immediate patching is not possible, restrict network access to SMB/RPC ports (139/445) to trusted hosts only.
  • Disable or block unnecessary MS-RPC services and named pipes that are not required for business operations.
  • Apply vendor advisories from Apple, HP, and SUSE for bundled or downstream Samba packages.
  • Monitor and segment file server networks so a compromised smbd cannot pivot freely.

Detection

  • Inspect SMB/RPC traffic for malformed or unusually large NDR requests targeting DFSEnum, RFNPCNEX, LsarAddPrivilegesToAccount, NetSetFileSecurity, or LsarLookupSids operations.
  • Monitor smbd process crashes or abnormal terminations, which can indicate heap corruption attempts.
  • Alert on unexpected outbound connections or child processes spawned by smbd.
  • Review host logs for signs of code execution in the context of the Samba service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=306172
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01067768
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html
http://osvdb.org/34699
http://osvdb.org/34731
http://osvdb.org/34733
http://secunia.com/advisories/25232 Vendor Advisory
http://secunia.com/advisories/25241 Vendor Advisory
http://secunia.com/advisories/25246 Vendor Advisory
http://secunia.com/advisories/25251 Vendor Advisory
http://secunia.com/advisories/25255 Vendor Advisory
http://secunia.com/advisories/25256 Vendor Advisory
http://secunia.com/advisories/25257 Vendor Advisory
http://secunia.com/advisories/25259 Vendor Advisory
http://secunia.com/advisories/25270 Vendor Advisory
http://secunia.com/advisories/25289
http://secunia.com/advisories/25391/
http://secunia.com/advisories/25567
http://secunia.com/advisories/25675
http://secunia.com/advisories/25772
http://secunia.com/advisories/26235
http://secunia.com/advisories/26909
http://secunia.com/advisories/27706
http://secunia.com/advisories/28292
http://security.gentoo.org/glsa/glsa-200705-15.xml
http://securityreason.com/securityalert/2702
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1
http://www.debian.org/security/2007/dsa-1291
http://www.kb.cert.org/vuls/id/773720 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2007:104
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html
http://www.osvdb.org/34732
http://www.redhat.com/support/errata/RHSA-2007-0354.html Vendor Advisory
http://www.samba.org/samba/security/CVE-2007-2446.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/468542/100/0/threaded

Track CVE-2007-2446 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7494Samba writable share library upload leads to remote code executionSamba versions from 3.5.0 up to (but not including) 4.6.4, 4.5.10 and 4.4.14 allow a malicious client to upload a shared library to a writable share …KEVEPSS 99%analysed5.5CVE-2020-1472Microsoft Netlogon elevation of privilege via vulnerable secure channel (Zerologon)CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlog…KEVEPSS 99%analysed10.0CVE-2015-0240Samba Netlogon ServerPasswordSet RPC uninitialized pointer code executionSamba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw a…EPSS 88%analysed10.0CVE-2012-1182Samba RPC code generator array length validation flaw allows remote code executionThe RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it v…EPSS 74%analysed10.0CVE-2004-0882Samba vulnerabilityBuffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT…EPSS 14%10.0CVE-2004-1154Samba vulnerabilityInteger overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (appl…EPSS 13%10.0CVE-2004-0600Samba vulnerabilityBuffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid …EPSS 29%10.0CVE-2003-0196Samba vulnerabilityMultiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by …EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2007-2446), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.