← Vulnerability feed

Vulnerability record · CVE-2007-2447 · published 14 May 2007

CVE-2007-2447: Samba smbd MS-RPC shell metacharacter command injection

Samba · Samba

Samba 3.0.0 through 3.0.25rc3 fails to sanitize shell metacharacters passed through MS-RPC functions in smbd. The SamrChangePassword path is reachable by unauthenticated remote attackers when the 'username map script' smb.conf option is enabled, while remote printer and file share management paths require authentication. Because the injected input reaches a shell, it allows arbitrary command execution on the server.

6.0 CVSS 2.0 Medium EPSS 50% · top 1.1%
6.0CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
111References
16 Jun 2026Last modified by NVD

Description

The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

AV:N/AC:M/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote command execution in a widely deployed service with a very high EPSS score, though the unauthenticated path depends on a non-default configuration option.

What it is

Samba 3.0.0 through 3.0.25rc3 fails to sanitize shell metacharacters passed through MS-RPC functions in smbd. The SamrChangePassword path is reachable by unauthenticated remote attackers when the 'username map script' smb.conf option is enabled, while remote printer and file share management paths require authentication. Because the injected input reaches a shell, it allows arbitrary command execution on the server.

Impact

An attacker can execute arbitrary commands with the privileges of the smbd process, leading to full compromise of the Samba host and any data or services it exposes. In the unauthenticated case, no credentials are needed at all.

Attack surface

Reached over the network via MS-RPC on Samba's SMB service; the CVSS vector AV:N/AC:M/Au:S indicates network access, medium complexity, and single authentication. The SamrChangePassword variant requires the non-default 'username map script' option to be enabled, while the printer and file share variants require an authenticated session.

Exploitation

The record is not listed in CISA KEV and carries no exploit-tagged references, but EPSS is very high (0.49759, 98.8th percentile), indicating strong likelihood of exploitation activity. No ransomware group association is documented.

What to do

  • Upgrade Samba to a version later than 3.0.25rc3 that contains the fix.
  • Disable the 'username map script' smb.conf option unless strictly required.
  • Restrict network access to SMB/MS-RPC ports (139/445) to trusted hosts only.
  • Run smbd with least privilege and avoid unnecessary printer and file share management exposure.
  • Monitor vendor advisories from Samba, Apple, HP and SUSE for backported patches.

Detection

  • Inspect smbd logs and process accounting for unexpected child processes spawned by smbd.
  • Alert on shell metacharacters (;, |, `, $(), &&) in SMB/MS-RPC request payloads or usernames.
  • Audit smb.conf for the 'username map script' option and flag any host where it is enabled.
  • Correlate outbound connections or command execution originating from Samba hosts with SMB traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=306172
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01067768
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=534
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html
http://secunia.com/advisories/25232 Vendor Advisory
http://secunia.com/advisories/25241 Vendor Advisory
http://secunia.com/advisories/25246 Vendor Advisory
http://secunia.com/advisories/25251 Vendor Advisory
http://secunia.com/advisories/25255 Vendor Advisory
http://secunia.com/advisories/25256 Vendor Advisory
http://secunia.com/advisories/25257 Vendor Advisory
http://secunia.com/advisories/25259 Vendor Advisory
http://secunia.com/advisories/25270 Vendor Advisory
http://secunia.com/advisories/25289
http://secunia.com/advisories/25567
http://secunia.com/advisories/25675
http://secunia.com/advisories/25772
http://secunia.com/advisories/26083
http://secunia.com/advisories/26235
http://secunia.com/advisories/26909
http://secunia.com/advisories/27706
http://secunia.com/advisories/28292
http://security.gentoo.org/glsa/glsa-200705-15.xml
http://securityreason.com/securityalert/2700
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1
http://www.debian.org/security/2007/dsa-1291
http://www.kb.cert.org/vuls/id/268336 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2007:104
http://www.novell.com/linux/security/advisories/2007_14_sr.html
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html
http://www.osvdb.org/34700
http://www.redhat.com/support/errata/RHSA-2007-0354.html
http://www.samba.org/samba/security/CVE-2007-2447.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/468565/100/0/threaded
http://www.securityfocus.com/archive/1/468670/100/0/threaded

Track CVE-2007-2447 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7494Samba writable share library upload leads to remote code executionSamba versions from 3.5.0 up to (but not including) 4.6.4, 4.5.10 and 4.4.14 allow a malicious client to upload a shared library to a writable share …KEVEPSS 99%analysed5.5CVE-2020-1472Microsoft Netlogon elevation of privilege via vulnerable secure channel (Zerologon)CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlog…KEVEPSS 99%analysed10.0CVE-2015-0240Samba Netlogon ServerPasswordSet RPC uninitialized pointer code executionSamba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw a…EPSS 88%analysed10.0CVE-2012-1182Samba RPC code generator array length validation flaw allows remote code executionThe RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it v…EPSS 74%analysed10.0CVE-2007-2446Samba smbd NDR parsing heap buffer overflows allow remote code executionSamba 3.0.0 through 3.0.25rc3 contains multiple heap-based buffer overflows in the NDR parsing code of smbd, reachable through crafted MS-RPC request…EPSS 78%analysed10.0CVE-2004-0882Samba vulnerabilityBuffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT…EPSS 14%10.0CVE-2004-1154Samba vulnerabilityInteger overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (appl…EPSS 13%10.0CVE-2004-0600Samba vulnerabilityBuffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid …EPSS 29%

Source: NIST National Vulnerability Database (record CVE-2007-2447), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.