Back to Database
Status published
Critical
CVE-2017-14746
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers...
Vulnerability Description
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-14746
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.samba.org/samba/security/CVE-2017-14746.html
- https://access.redhat.com/errata/RHSA-2017:3278
- https://www.debian.org/security/2017/dsa-4043
- https://access.redhat.com/errata/RHSA-2017:3260
- http://www.securitytracker.com/id/1039856
- http://www.securityfocus.com/bid/101907
- https://access.redhat.com/errata/RHSA-2017:3261
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://security.gentoo.org/glsa/201805-07
- http://www.ubuntu.com/usn/USN-3486-1
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
More from samba
View All →CVE-2022-29869
cifs-utils through 6.14, with verbose logging, can cause an information...
Medium
5.3
CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows...
High
7.4
CVE-2022-27239
In cifs-utils through 6.14, a stack-based buffer overflow when parsing...
High
7.8
CVE-2021-43566
All versions of Samba prior to 4.13.16 are vulnerable to...
Low
2.5
CVE-2020-14342
It was found that cifs-utils' mount.cifs was invoking a shell...
Medium
4.4
Affected Vendor
samba
View all reports →Affected Software
samba, ubuntu linux, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Vulnerable Versions:
4.0.0, 4.5.0, 4.6.0, 4.7.0, 14.04, 16.04, 17.04, 17.10, 8.0, 9.0, 6.0, 7.0
Timeline
Official Publish:
November 27th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.