CVE-2017-7494: Samba Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-03-30. EPSS: 99.4% chance of exploitation in the next 30 days.

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Samba Samba: from 3.5.0, before 4.4.0 (fixed in 4.4.0); from 4.4.0, before 4.4.14 (fixed in 4.4.14); from 4.5.0, before 4.5.10 (fixed in 4.5.10); from 4.6.0, before 4.6.4 (fixed in 4.6.4)

Published 2017-05-30. Last modified 2026-06-17.