#VU117238 OS Command Injection in Samba - CVE-2025-10230
Published: October 15, 2025 / Updated: October 24, 2025
Samba
Samba
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in WINS server. A remote attacker can send a specially crafted hostname to the server containing shell commands and execute arbitrary OS commands on the target system.