← Vulnerability feed

Vulnerability record · CVE-2012-1182 · published 10 April 2012

CVE-2012-1182: Samba RPC code generator array length validation flaw allows remote code execution

Samba · Samba

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it validates array memory allocation. A remote attacker can send a crafted RPC call to trigger memory corruption and execute arbitrary code. The flaw is remotely reachable and pre-authentication per the CVSS vector, making it a serious risk to exposed Samba services.

10.0 CVSS 2.0 High EPSS 74% · top 0.5% CWE-189 · CWE-189
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
54References
16 Jun 2026Last modified by NVD

Description

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus very high EPSS, warrants critical priority despite no confirmed KEV listing.

What it is

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 validates an array length inconsistently with how it validates array memory allocation. A remote attacker can send a crafted RPC call to trigger memory corruption and execute arbitrary code. The flaw is remotely reachable and pre-authentication per the CVSS vector, making it a serious risk to exposed Samba services.

Impact

An attacker gains arbitrary code execution on the Samba host, typically with the privileges of the Samba service, which on many deployments is root. This can lead to full host compromise and lateral movement into the network.

Attack surface

Reached over the network via a crafted RPC call to a Samba service; the CVSS 2.0 vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing Samba RPC services is potentially reachable.

Exploitation

Not listed in CISA KEV and no reference tags indicate a public exploit, but EPSS is very high (0.74371, 99.467th percentile), suggesting elevated likelihood of exploitation activity. The record does not confirm in-the-wild exploitation.

What to do

  • Upgrade Samba to 3.4.16, 3.5.14, 3.6.4 or later, or apply the vendor patch for your distribution.
  • Restrict network access to Samba RPC ports (TCP 445 and 139) to trusted hosts only.
  • Disable or block SMB/RPC exposure on internet-facing systems and segment file-sharing services.
  • Monitor vendor advisories (Debian, Fedora, openSUSE, Apple, Mandriva) for the corresponding fixed packages and apply them.
  • If patching is delayed, consider disabling unnecessary Samba services or running them under a least-privilege account.

Detection

  • Monitor Samba logs for malformed or unusual RPC requests and crashes of smbd.
  • Use network IDS signatures for crafted RPC calls targeting Samba array length handling.
  • Watch for unexpected process crashes or restarts of smbd that could indicate exploitation attempts.
  • Correlate SMB/RPC traffic from untrusted sources with host-level process anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078258.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078726.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078836.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080567.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.html
http://marc.info/?l=bugtraq&m=133951282306605&w=2
http://marc.info/?l=bugtraq&m=134323086902585&w=2
http://secunia.com/advisories/48751
http://secunia.com/advisories/48754
http://secunia.com/advisories/48816
http://secunia.com/advisories/48818
http://secunia.com/advisories/48844
http://secunia.com/advisories/48873
http://secunia.com/advisories/48879
http://secunia.com/advisories/48999
http://support.apple.com/kb/HT5281
http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578
http://www.debian.org/security/2012/dsa-2450
http://www.mandriva.com/security/advisories?name=MDVSA-2012:055
http://www.samba.org/samba/history/samba-3.6.4.html
http://www.securitytracker.com/id?1026913
http://www.ubuntu.com/usn/USN-1423-1
https://www.samba.org/samba/security/CVE-2012-1182 Vendor Advisory
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078258.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078726.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078836.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080567.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00014.html
http://marc.info/?l=bugtraq&m=133951282306605&w=2
http://marc.info/?l=bugtraq&m=134323086902585&w=2
http://secunia.com/advisories/48751
http://secunia.com/advisories/48754

Track CVE-2012-1182 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7494Samba writable share library upload leads to remote code executionSamba versions from 3.5.0 up to (but not including) 4.6.4, 4.5.10 and 4.4.14 allow a malicious client to upload a shared library to a writable share …KEVEPSS 99%analysed5.5CVE-2020-1472Microsoft Netlogon elevation of privilege via vulnerable secure channel (Zerologon)CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlog…KEVEPSS 99%analysed10.0CVE-2015-0240Samba Netlogon ServerPasswordSet RPC uninitialized pointer code executionSamba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw a…EPSS 88%analysed10.0CVE-2007-2446Samba smbd NDR parsing heap buffer overflows allow remote code executionSamba 3.0.0 through 3.0.25rc3 contains multiple heap-based buffer overflows in the NDR parsing code of smbd, reachable through crafted MS-RPC request…EPSS 78%analysed10.0CVE-2004-0882Samba vulnerabilityBuffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT…EPSS 14%10.0CVE-2004-1154Samba vulnerabilityInteger overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (appl…EPSS 13%10.0CVE-2004-0600Samba vulnerabilityBuffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid …EPSS 29%10.0CVE-2003-0196Samba vulnerabilityMultiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by …EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2012-1182), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.