CVE-2010-2063 describes a buffer overflow vulnerability in the SMB1 packet chaining implementation within Samba's smbd daemon, affecting versions 3.0.x before 3.3.13. This flaw allows remote attackers to trigger a denial of service through memory corruption, potentially leading to arbitrary code execution. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog, exploit intelligence indicates the existence of a Metasploit module and an ExploitDB entry, suggesting readily available exploit code. Community discussion and media coverage are limited, but the high EPSS and FAUCET Risk Scores highlight its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, <= 3.3.12CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* | ||
9.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.