CVE Vulnerabilities

CVE-2007-2444

Improper Privilege Management

Published: May 14, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.0.23d (including)3.0.23d (including)
SambaSamba3.0.24 (including)3.0.24 (including)
SambaSamba3.0.25-pre2 (including)3.0.25-pre2 (including)
SambaUbuntudevel*
SambaUbuntufeisty*

Potential Mitigations

References