Security Advisory

CVE-2025-10230

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-07 19:42:06
Last updated 2026-06-29 21:25:47
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.