CVE-2007-2446

Samba 3.0.0-3.0.25rc3 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 9 public exploits for CVE-2007-2446. PoCs published by Metasploit, Adriano Lima, hdm, including Metasploit module auxiliary/dos/samba/lsa_transnames_heap.

AI-analyzed exploit summary This is a Metasploit module exploiting a heap overflow in Samba's LSA RPC service (CVE-2007-2446). It uses the TALLOC chunk overwrite method to achieve remote code execution on vulnerable Samba versions (3.0.21-3.0.24).

Description

Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).

Exploits (9)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/16859

This is a Metasploit module exploiting a heap overflow in Samba's LSA RPC service (CVE-2007-2446). It uses the TALLOC chunk overwrite method to achieve remote code execution on vulnerable Samba versions (3.0.21-3.0.24).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba 3.0.21-3.0.24
No auth needed
Prerequisites: Network access to vulnerable Samba server · Samba version 3.0.21-3.0.24 · Log level parameter not higher than 2
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotesolaris
https://www.exploit-db.com/exploits/16329

This exploit triggers a heap overflow in the LSA RPC service of Samba versions 3.0.21-3.0.24 by overwriting TALLOC chunks, leading to remote code execution. It uses a brute-force approach to target specific memory addresses on Solaris systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: Samba 3.0.21-3.0.24
No auth needed
Prerequisites: Network access to the target SMB service · Samba version 3.0.21-3.0.24 · Log level parameter set to 2 or lower
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteosx
https://www.exploit-db.com/exploits/16875

This Metasploit module exploits a heap overflow in Samba's LSA RPC service (CVE-2007-2446) by manipulating the szone_free() function to overwrite memory structures, leading to arbitrary code execution on vulnerable Mac OS X systems running Samba 3.0.10.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Samba 3.0.10 on Mac OS X 10.4.x
Auth required
Prerequisites: Network access to the SMB service · Valid SMB credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Adriano Lima · rubyremotelinux
https://www.exploit-db.com/exploits/9950

This Metasploit module exploits a heap overflow in Samba's LSA RPC service (CVE-2007-2446) via the TALLOC chunk overwrite method, targeting specific Linux distributions with brute-force return address guessing.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Samba 3.0.21-3.0.24
Auth required
Prerequisites: Network access to SMB service · Valid SMB credentials · Samba version 3.0.21-3.0.24 · Log level <= 2
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/samba/lsa_transnames_heap.rb

This Metasploit module exploits a heap overflow vulnerability in the LSA RPC service of Samba (CVE-2007-2446) by sending a maliciously crafted DCERPC request to trigger a denial-of-service (DoS) condition. The exploit targets the `LsarLookupSids` function with an oversized buffer to crash the service.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Samba (versions affected by CVE-2007-2446)
No auth needed
Prerequisites: Network access to the SMB service · Samba with vulnerable LSA RPC service
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/samba/lsa_addprivs_heap.rb

This Metasploit module exploits a heap overflow in the LSA RPC service of Samba (CVE-2007-2446) by sending a malformed DCERPC request to trigger a denial-of-service (DoS) condition. The exploit targets the `LsarAddPrivilegesToAccount` function with a crafted stub to overflow the heap.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Samba (versions affected by CVE-2007-2446)
No auth needed
Prerequisites: Network access to the SMB service · Samba with vulnerable LSA RPC service
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Ramon de C Valle · rubypocsolaris
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/solaris/samba/lsa_transnames_heap.rb

This Metasploit module exploits a heap overflow in Samba's LSA RPC service (CVE-2007-2446) via a TALLOC chunk overwrite, targeting Samba versions 3.0.21-3.0.24 on Solaris. It uses brute-force return address targeting to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba 3.0.21-3.0.24
No auth needed
Prerequisites: Network access to the Samba service · SMB pipe access (LSARPC) · Samba log level <= 2
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by Ramon de C Valle · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/samba/lsa_transnames_heap.rb

This Metasploit module exploits a heap overflow in Samba's LSA RPC service (CVE-2007-2446) using the TALLOC chunk overwrite method, targeting specific Linux distributions and versions (3.0.21-3.0.24). It includes brute-force techniques for various memory layouts and architectures.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Samba 3.0.21-3.0.24
No auth needed
Prerequisites: Network access to vulnerable Samba service · SMB pipe access (LSARPC) · Log level <= 2
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Ramon de C Valle · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/samba/lsa_transnames_heap.rb

This Metasploit module exploits a heap overflow in Samba's LSA RPC service (CVE-2007-2446) by manipulating the `szone_free()` function to overwrite memory structures, leading to arbitrary code execution on macOS systems running Samba 3.0.10.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Samba 3.0.10 on Mac OS X 10.4.x (x86/PPC)
Auth required
Prerequisites: Network access to SMB service · Valid SMB credentials · Target running vulnerable Samba version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (75)

Core 75
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.samba.org/samba/security/CVE-2007-2446.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34316
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25257
Various Sources vendor-advisory x_refsource_suse
http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200705-15.xml
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468672/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25289
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468673/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468674/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2732
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1805
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3229
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25772
Vendor Advisory vendor-advisory x_refsource_openpkg
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25391/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24198
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468675/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25270
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468670/100/0/threaded
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34314
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2281
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-07-033.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2210
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34311
Vendor Advisory vendor-advisory x_refsource_trustix
http://www.trustix.org/errata/2007/0017/
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-460-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34312
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2702
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25567
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/34731
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-07-031.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/34699
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25241
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28292
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:104
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25256
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-1366
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25259
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34309
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/34732
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468542/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018050
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23973
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-07-030.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26909
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0050
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27706
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1291
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/773720
Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=306172
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25232
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25251
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25246
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468680/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24197
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/34733
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11415
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25159
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-07-032.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25255
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24196
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0354.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24195
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-07-029.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26235
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25675
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2079

Scores

EPSS 0.7766
EPSS Percentile 99.5%

Details

CWE
CWE-119
Status published
Products (30)
samba/samba 3.0.0
samba/samba 3.0.1
samba/samba 3.0.2
samba/samba 3.0.2a
samba/samba 3.0.10
samba/samba 3.0.11
samba/samba 3.0.12
samba/samba 3.0.13
samba/samba 3.0.14
samba/samba 3.0.14a
... and 20 more
Published May 14, 2007
Tracked Since Feb 18, 2026