Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1050

19
FAUCET Score

CVE-2018-1050 is a denial-of-service vulnerability affecting all versions of Samba from 4.0.0 onwards when the RPC spoolss service is configured as an external daemon. It stems from missing input sanitization, allowing attackers to crash the print spooler service. With a CVSS score of 4.3 (Medium), it requires network access but no authentication or user interaction, leading to a low impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
17.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:lts:*:*:*
>= 3.6.0, < 4.5.16CPE matchmatch criteria
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.56%
Probability of exploitation in next 30 days
EPSS Percentile
93.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0656 is in the 98th percentile among its peer group of 1,802 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

microsoftpatch availablevia msrc
Product: 16863-16823Fixed in: 4.12.5-6
microsoftpatch availablevia msrc
Product: cbl2 samba 4.12.5-6 on CBL Mariner 2.0Fixed in: 4.12.5-6
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 4.12.5-6
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 4.12.5-6
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: samba-0:4.8.3-4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 6Fixed in: libtalloc-0:2.1.11-1.el6rhs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 6Fixed in: libtdb-0:1.3.15-4.el6rhs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 6Fixed in: libtevent-0:0.9.35-1.el6rhs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 6Fixed in: samba-0:4.7.5-110.el6rhs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 7Fixed in: libtalloc-0:2.1.11-1.el7rhgs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 7Fixed in: libtdb-0:1.3.15-4.el7rhgs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 7Fixed in: libtevent-0:0.9.35-1.el7rhgs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.4 for RHEL 7Fixed in: samba-0:4.7.5-110.el7rhgs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: samba-0:3.6.23-51.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: samba4-0:4.2.10-15.el6
View patch

Vendor Advisories (3)

microsoft2022-Jan/CVE-2018-1050

CVE-2018-1050

Jan 11, 2022
microsoft2018-Mar/CVE-2018-1050Moderate

All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.

Mar 13, 2018
redhatCVE-2018-1050Low

samba: NULL pointer dereference in printer server process

Mar 13, 2018

References

access.redhat.com / errata/RHSA-2018:1860
Third Party Advisory
access.redhat.com / errata/RHSA-2018:1883
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2612
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2613
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3056
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
help.ecostruxureit.com / display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
Third Party Advisory
lists.debian.org / debian-lts-announce/2018/03/msg00024.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2019/04/msg00013.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/201805-07
Third Party Advisory
security.netapp.com / advisory/ntap-20180313-0001
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
usn.ubuntu.com / 3595-1
Third Party Advisory
usn.ubuntu.com / 3595-2
Third Party Advisory
debian.org / security/2018/dsa-4135
Third Party Advisory
samba.org / samba/security/CVE-2018-1050.html
MitigationVendor Advisory
securityfocus.com / bid/103387
Third Party AdvisoryVDB Entry
securitytracker.com / id/1040493
Third Party AdvisoryVDB Entry