CVE-2007-2447

Samba 3.0.0-3.0.25rc3 - Command Injection

Title source: llm

Description

The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

Exploits (39)

nomisec WORKING POC 62 stars
by amriunix · poc
https://github.com/amriunix/CVE-2007-2447
nomisec WORKING POC 5 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2007-2447
nomisec WORKING POC 4 stars
by Unix13 · poc
https://github.com/Unix13/metasploitable2
nomisec WORKING POC 3 stars
by Ziemni · poc
https://github.com/Ziemni/CVE-2007-2447-in-Python
nomisec WORKING POC 2 stars
by Alien0ne · poc
https://github.com/Alien0ne/CVE-2007-2447
nomisec WORKING POC 2 stars
by xbufu · poc
https://github.com/xbufu/CVE-2007-2447
nomisec WORKING POC 1 stars
by s4msec · poc
https://github.com/s4msec/CVE-2007-2447
nomisec WRITEUP 1 stars
by SeifEldienAhmad · poc
https://github.com/SeifEldienAhmad/Penetration-Testing-on-Metasploitable2
nomisec WORKING POC 1 stars
by ozuma · poc
https://github.com/ozuma/CVE-2007-2447
nomisec WORKING POC 1 stars
by Aviksaikat · poc
https://github.com/Aviksaikat/CVE-2007-2447
nomisec WORKING POC 1 stars
by 3x1t1um · poc
https://github.com/3x1t1um/CVE-2007-2447
nomisec WORKING POC
by WildfootW · poc
https://github.com/WildfootW/CVE-2007-2447_Samba_3.0.25rc3
nomisec WORKING POC
by xlcc4096 · poc
https://github.com/xlcc4096/exploit-CVE-2007-2447
nomisec STUB
by JoseBarrios · poc
https://github.com/JoseBarrios/CVE-2007-2447
nomisec STUB
by 3t4n · poc
https://github.com/3t4n/samba-3.0.24-CVE-2007-2447-vunerable-
nomisec WORKING POC
by Nosferatuvjr · poc
https://github.com/Nosferatuvjr/Samba-Usermap-exploit
nomisec WRITEUP
by DevinLiggins14 · poc
https://github.com/DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2
github WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/samba-usermap-rce (CVE-2007-2447)
nomisec WORKING POC
by b1fair · poc
https://github.com/b1fair/smb_usermap
nomisec WORKING POC
by MikeRega7 · poc
https://github.com/MikeRega7/CVE-2007-2447-RCE
nomisec WORKING POC
by HerculesRD · poc
https://github.com/HerculesRD/PyUsernameMapScriptRCE
nomisec WORKING POC
by G01d3nW01f · poc
https://github.com/G01d3nW01f/CVE-2007-2447
nomisec WORKING POC
by elphon · poc
https://github.com/elphon/CVE-2007-2447-Exploit
nomisec WORKING POC
by bdunlap9 · poc
https://github.com/bdunlap9/CVE-2007-2447_python
nomisec WORKING POC
by foudadev · poc
https://github.com/foudadev/CVE-2007-2447
nomisec WORKING POC
by MrRoma577 · poc
https://github.com/MrRoma577/exploit_cve-2007-2447_again
nomisec WORKING POC
by Juantos · poc
https://github.com/Juantos/cve-2007-2447
nomisec WORKING POC
by IamLucif3r · poc
https://github.com/IamLucif3r/CVE-2007-2447-Exploit
nomisec STUB
by testaross4 · poc
https://github.com/testaross4/CVE-2007-2447
nomisec WORKING POC
by 0xKn · poc
https://github.com/0xKn/CVE-2007-2447
nomisec WORKING POC
by ShivamDey · poc
https://github.com/ShivamDey/Samba-CVE-2007-2447-Exploit
nomisec WORKING POC
by b33m0x00 · poc
https://github.com/b33m0x00/CVE-2007-2447
nomisec WORKING POC
by nika0x38 · poc
https://github.com/nika0x38/CVE-2007-2447
github WORKING POC
by Boon-Rekcah · pythonpoc
https://github.com/Boon-Rekcah/CVE-Exploits/tree/main/CVE-2007-2447( Samba 3.0.20 ).py
nomisec WRITEUP
by nulltrace1336 · poc
https://github.com/nulltrace1336/Samba-Exploit-CVE-2007-2447
nomisec WORKING POC
by r0tn3x · poc
https://github.com/r0tn3x/CVE-2007-2447
nomisec WORKING POC
by abdulsaabir · poc
https://github.com/abdulsaabir/CVE-2007-2447
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/16320
metasploit WORKING POC EXCELLENT
by jduck · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/samba/usermap_script.rb

Scores

EPSS 0.5096
EPSS Percentile 97.8%

Classification

Status draft

Affected Products (42)

samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba
... and 27 more

Timeline

Published May 14, 2007
Tracked Since Feb 18, 2026