CVE-2017-7494
KEV RANSOMWAREHIGH 10.0EPSS 99.4%
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 99.45% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-03-30, used in ransomware campaigns
- Published
- 2017-05-30
- Updated
- 2025-10-21
Proof-of-concept exploits (25)
- 00mjk/exploit-CVE-2017-74941★ · 2022-05-08
- 0xm4ud/noSAMBAnoCRY-CVE-2017-74946★ · 2021-08-27
- BJ-PXD/Explotacion-de-Vulnerabiliddes-bee-box0★ · 2024-08-28
- Hansindu-M/CVE-2017-7494_IT191153440★ · 2020-05-11
- NhutMinh2801/CVE_2017_74940★ · 2023-12-12
- Zer0d0y/Samba-CVE-2017-74941★ · 2018-03-28
- adjaliya/-CVE-2017-7494-Samba-Exploit-POC0★ · 2021-09-29
- amaaledi/SNP_Project_Linux_Vulnerability_Exploit0★ · 2021-06-03
- ashueep/SMB-Exploit1★ · 2020-12-05
- betab0t/cve-2017-7494181★ · 2017-07-26
- brianwrf/SambaHunter57★ · 2021-10-31
- caique-garbim/CVE-2017-7494_SambaCry7★ · 2022-11-01
- cved-sources/cve-2017-74940★ · 2021-04-15
- cyberharsh/Samba74940★ · 2020-09-07
- d3fudd/CVE-2017-7494_SambaCry7★ · 2022-11-01
- giuseppsss/sambacry-pw21★ · 2020-09-30
- homjxi0e/CVE-2017-74940★ · 2017-05-26
- incredible1yu/CVE-2017-74940★ · 2018-05-10
- john-80/cve-2017-74940★ · 2019-12-30
- joxeankoret/CVE-2017-7494259★ · 2021-03-09
- m4udSec/noSAMBAnoCRY-CVE-2017-74946★ · 2021-08-27
- opsxcq/exploit-CVE-2017-7494380★ · 2022-12-27
- the-aerospace-corporation/counter-reconnaissance-program5★ · 2020-12-03
- YonLiud/CVE-2017-7494
- sudlit/CVE-2017-7494