top of page
perceptive_background_267k.jpg

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password sc…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 14:02:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Network Infrastructure, Identity & Access

A critical vulnerability in Samba file servers and domain controllers allows remote attackers to achieve command execution through improper escaping of shell meta-characters in the 'check password script' feature. The flaw occurs when the script is configured with the %u substitution character, allowing client-controlled usernames to be passed without proper sanitization. This primarily affects non-standard configurations where the check password script uses %u and the samba-dcerpcd service runs as a system service. The vulnerability enables remote code execution on affected systems through exploitation of the misconfigured password checking mechanism.

Technical details

Mitigation steps:

Affected products:

Samba

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page