Vulnerability record · CVE-2007-2447 · published 14 May 2007
CVE-2007-2447: Samba smbd MS-RPC shell metacharacter command injection
Samba · Samba
Samba 3.0.0 through 3.0.25rc3 fails to sanitize shell metacharacters passed through MS-RPC functions in smbd. The SamrChangePassword path is reachable by unauthenticated remote attackers when the 'username map script' smb.conf option is enabled, while remote printer and file share management paths require authentication. Because the injected input reaches a shell, it allows arbitrary command execution on the server.
Description
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.
AV:N/AC:M/Au:S/C:P/I:P/A:P
Automated analysis
high priorityRemote command execution in a widely deployed service with a very high EPSS score, though the unauthenticated path depends on a non-default configuration option.
What it is
Samba 3.0.0 through 3.0.25rc3 fails to sanitize shell metacharacters passed through MS-RPC functions in smbd. The SamrChangePassword path is reachable by unauthenticated remote attackers when the 'username map script' smb.conf option is enabled, while remote printer and file share management paths require authentication. Because the injected input reaches a shell, it allows arbitrary command execution on the server.
Impact
An attacker can execute arbitrary commands with the privileges of the smbd process, leading to full compromise of the Samba host and any data or services it exposes. In the unauthenticated case, no credentials are needed at all.
Attack surface
Reached over the network via MS-RPC on Samba's SMB service; the CVSS vector AV:N/AC:M/Au:S indicates network access, medium complexity, and single authentication. The SamrChangePassword variant requires the non-default 'username map script' option to be enabled, while the printer and file share variants require an authenticated session.
Exploitation
The record is not listed in CISA KEV and carries no exploit-tagged references, but EPSS is very high (0.49759, 98.8th percentile), indicating strong likelihood of exploitation activity. No ransomware group association is documented.
What to do
- Upgrade Samba to a version later than 3.0.25rc3 that contains the fix.
- Disable the 'username map script' smb.conf option unless strictly required.
- Restrict network access to SMB/MS-RPC ports (139/445) to trusted hosts only.
- Run smbd with least privilege and avoid unnecessary printer and file share management exposure.
- Monitor vendor advisories from Samba, Apple, HP and SUSE for backported patches.
Detection
- Inspect smbd logs and process accounting for unexpected child processes spawned by smbd.
- Alert on shell metacharacters (;, |, `, $(), &&) in SMB/MS-RPC request payloads or usernames.
- Audit smb.conf for the 'username map script' option and flag any host where it is enabled.
- Correlate outbound connections or command execution originating from Samba hosts with SMB traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2447 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2447), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.