CVE-2017-7494, also known as SambaCry, is a critical remote code execution vulnerability affecting Samba versions 3.5.0 through 4.6.4, 4.5.10, and 4.4.14. This flaw allows an unauthenticated attacker to upload a malicious shared library to a writable share and then compel the Samba server to load and execute it. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, including in known ransomware campaigns, and has readily available exploit modules in frameworks like Metasploit. The high EPSS score, extensive community discussion, and numerous media reports underscore its significant risk and widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 4.4.0CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.4.0, < 4.4.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.5.0, < 4.5.10CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.6.0, < 4.6.4CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.