Vulnerability record · CVE-2014-3560 · published 6 August 2014
CVE-2014-3560: Samba nmbd heap memory corruption enables remote code execution
Canonical · Ubuntu Linux
The NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 contains a heap memory corruption flaw caused by a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h. A remote attacker can send unspecified vectors that modify heap memory, potentially leading to arbitrary code execution. The record does not specify the exact packet or protocol path beyond nmbd.
Description
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h.
AV:A/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with complete impact, and EPSS predicts high exploitation activity, though it is not in KEV and requires adjacent network access.
What it is
The NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 contains a heap memory corruption flaw caused by a sizeof operation on an incorrect variable in the unstrcpy macro in string_wrappers.h. A remote attacker can send unspecified vectors that modify heap memory, potentially leading to arbitrary code execution. The record does not specify the exact packet or protocol path beyond nmbd.
Impact
An attacker can corrupt heap memory in nmbd and potentially execute arbitrary code with the privileges of the Samba daemon. The CVSS 2.0 vector indicates complete loss of confidentiality, integrity and availability on the affected host.
Attack surface
The flaw is reachable over the network via the NetBIOS name service handled by nmbd, as reflected by the AV:A (adjacent network) vector. No authentication is required (Au:N), but the AC:M rating indicates some conditions must be met for a successful attack; the description does not state whether user interaction is needed.
Exploitation
CVE-2014-3560 is not listed in CISA KEV and no ransomware groups are documented using it. EPSS gives a 30-day probability of 0.56378 (99.008 percentile), indicating high predicted exploitation activity, but the record contains no reference tagged as an exploit or proof of concept.
What to do
- Upgrade Samba to 4.0.21 or 4.1.11 or later, or apply the vendor patches referenced in the Samba security advisory and distribution advisories.
- If immediate patching is not possible, restrict network access to nmbd/NetBIOS name service ports to trusted hosts and segments only.
- Disable or stop the nmbd service on systems that do not require NetBIOS name resolution.
- Monitor distribution advisories (Ubuntu USN-2305-1, Red Hat, Fedora, openSUSE) and apply the corresponding package updates.
- Segment or firewall legacy NetBIOS traffic at network boundaries to reduce exposure to adjacent attackers.
Detection
- Monitor nmbd process crashes or abnormal terminations and correlate with NetBIOS traffic from unexpected sources.
- Inspect network traffic to NetBIOS name service ports for malformed or unusually sized packets targeting nmbd.
- Review system logs and audit records for unexpected child processes or command execution spawned by the Samba/nmbd service account.
- Track Samba package versions across hosts and alert on systems still running 4.0.x before 4.0.21 or 4.1.x before 4.1.11.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-3560 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.