Vulnerability record · CVE-2012-1182 · published 10 April 2012
CVE-2012-1182: Samba RPC code generator array length validation flaw allows remote code execution
Samba · Samba
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it validates array memory allocation. A remote attacker can send a crafted RPC call to trigger memory corruption and execute arbitrary code. The flaw is remotely reachable and pre-authentication per the CVSS vector, making it a serious risk to exposed Samba services.
Description
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus very high EPSS, warrants critical priority despite no confirmed KEV listing.
What it is
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it validates array memory allocation. A remote attacker can send a crafted RPC call to trigger memory corruption and execute arbitrary code. The flaw is remotely reachable and pre-authentication per the CVSS vector, making it a serious risk to exposed Samba services.
Impact
An attacker gains arbitrary code execution on the Samba host, typically with the privileges of the Samba service, which on many deployments is root. This can lead to full host compromise and lateral movement into the network.
Attack surface
Reached over the network via a crafted RPC call to a Samba service; the CVSS 2.0 vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing Samba RPC services is potentially reachable.
Exploitation
Not listed in CISA KEV and no reference tags indicate a public exploit, but EPSS is very high (0.74371, 99.467th percentile), suggesting elevated likelihood of exploitation activity. The record does not confirm in-the-wild exploitation.
What to do
- Upgrade Samba to 3.4.16, 3.5.14, 3.6.4 or later, or apply the vendor patch for your distribution.
- Restrict network access to Samba RPC ports (TCP 445 and 139) to trusted hosts only.
- Disable or block SMB/RPC exposure on internet-facing systems and segment file-sharing services.
- Monitor vendor advisories (Debian, Fedora, openSUSE, Apple, Mandriva) for the corresponding fixed packages and apply them.
- If patching is delayed, consider disabling unnecessary Samba services or running them under a least-privilege account.
Detection
- Monitor Samba logs for malformed or unusual RPC requests and crashes of smbd.
- Use network IDS signatures for crafted RPC calls targeting Samba array length handling.
- Watch for unexpected process crashes or restarts of smbd that could indicate exploitation attempts.
- Correlate SMB/RPC traffic from untrusted sources with host-level process anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1182 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1182), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.