Vulnerability record · CVE-2015-0240 · published 24 February 2015
CVE-2015-0240: Samba Netlogon ServerPasswordSet RPC uninitialized pointer code execution
Redhat · Enterprise Linux
Samba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw allows a remote, unauthenticated attacker to execute arbitrary code on the Samba server. It affects Samba 3.5.x, 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5.
Description
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with remote unauthenticated code execution and very high EPSS score make this a critical risk for exposed Samba servers.
What it is
Samba's smbd Netlogon server frees an uninitialized stack pointer when handling crafted ServerPasswordSet RPC requests. This memory corruption flaw allows a remote, unauthenticated attacker to execute arbitrary code on the Samba server. It affects Samba 3.5.x, 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5.
Impact
A remote attacker can execute arbitrary code with the privileges of the smbd process, typically root, leading to full compromise of the Samba server. This could allow data theft, service disruption, or use of the host as a pivot point.
Attack surface
The flaw is reachable over the network via crafted Netlogon packets that invoke the ServerPasswordSet RPC API. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/Au:N.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a 87.6% probability of exploitation in the next 30 days (99.75th percentile), suggesting high likelihood of active exploitation. No reference tags indicate public exploit code, but the technical details are publicly documented.
What to do
- Apply vendor patches immediately; upgrade Samba to 3.6.25, 4.0.25, 4.1.17, 4.2.0rc5 or later as applicable.
- Restrict network access to Samba services (TCP 445, 139) to trusted hosts only.
- Disable the Netlogon service or ServerPasswordSet RPC if not required.
- Monitor vendor advisories for updated patches and apply them promptly.
Detection
- Monitor Samba logs for crashes or abnormal termination of smbd processes.
- Inspect network traffic for unusual Netlogon RPC calls, especially ServerPasswordSet, from untrusted sources.
- Use endpoint detection to flag unexpected child processes or command execution spawned by smbd.
- Check for signs of compromise such as new files, users, or outbound connections originating from the Samba server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0240 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0240), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.