CVE-2017-7494

CRITICAL KEV RANSOMWARE LAB

Samba is_known_pipename() Arbitrary Module Load

Title source: metasploit

Description

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

Exploits (28)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/42084
exploitdb WORKING POC VERIFIED
by steelo · pythonremotelinux
https://www.exploit-db.com/exploits/42060
github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2017-7494.md
nomisec WORKING POC 381 stars
by opsxcq · remote
https://github.com/opsxcq/exploit-CVE-2017-7494
nomisec WORKING POC 260 stars
by joxeankoret · remote
https://github.com/joxeankoret/CVE-2017-7494
nomisec WORKING POC 181 stars
by betab0t · remote
https://github.com/betab0t/cve-2017-7494
nomisec SCANNER 63 stars
by Waffles-2 · poc
https://github.com/Waffles-2/SambaCry
nomisec WORKING POC 57 stars
by brianwrf · remote
https://github.com/brianwrf/SambaHunter
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2017-7494.md
nomisec WORKING POC 7 stars
by d3fudd · remote
https://github.com/d3fudd/CVE-2017-7494_SambaCry
nomisec WORKING POC 5 stars
by 0xm4ud · remote
https://github.com/0xm4ud/noSAMBAnoCRY-CVE-2017-7494
nomisec WORKING POC 4 stars
by I-Rinka · poc
https://github.com/I-Rinka/BIT-EternalBlue-for-macOS_Linux
gitlab WORKING POC 1 stars
by baerle · remote
https://gitlab.com/baerle/exploit-cve-2017-7494
nomisec WORKING POC 1 stars
by 00mjk · remote
https://github.com/00mjk/exploit-CVE-2017-7494
nomisec WRITEUP 1 stars
by Zer0d0y · poc
https://github.com/Zer0d0y/Samba-CVE-2017-7494
gitlab WORKING POC
by 0x1 · remote
https://gitlab.com/0x1/CVE-2017-7494
nomisec WORKING POC
by Zanex360 · poc
https://github.com/Zanex360/cdt-vulnsamba-deploy
nomisec STUB
by Zanex360 · poc
https://github.com/Zanex360/cdt-samba-deploy
nomisec WORKING POC
by sudlit · remote
https://github.com/sudlit/CVE-2017-7494
nomisec STUB
by FelipeR-UFBA · poc
https://github.com/FelipeR-UFBA/cve-2017-7494-fixed
nomisec WRITEUP
by adjaliya · poc
https://github.com/adjaliya/-CVE-2017-7494-Samba-Exploit-POC
nomisec WORKING POC
by cved-sources · poc
https://github.com/cved-sources/cve-2017-7494
nomisec WRITEUP
by Hansindu-M · poc
https://github.com/Hansindu-M/CVE-2017-7494_IT19115344
nomisec NO CODE
by john-80 · poc
https://github.com/john-80/cve-2017-7494
nomisec WORKING POC
by incredible1yu · remote
https://github.com/incredible1yu/CVE-2017-7494
nomisec WORKING POC
by homjxi0e · remote
https://github.com/homjxi0e/CVE-2017-7494
metasploit WORKING POC EXCELLENT
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/samba/is_known_pipename.rb

References (17)

Scores

CVSS v3 9.8
EPSS 0.9418
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull vulnerables/cve-2017-7494
+20 more repos

Details

CISA KEV 2023-03-30
VulnCheck KEV 2017-12-05
InTheWild.io 2017-07-20
ENISA EUVD EUVD-2017-16511
Ransomware Use Confirmed
CWE
CWE-94
Status published
Products (3)
debian/debian_linux 8.0
samba/samba 3.5.0 - 4.4.0
Samba/samba since 3.5.0
Published May 30, 2017
KEV Added Mar 30, 2023
Tracked Since Feb 18, 2026