Samba Remote Code Execution Vulnerability

Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.

Published 14 Aug 2026Updated 14 Aug 202625 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.

Affected versions

Samba: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 42060Samba 3.5.0 - Remote Code Executionsteelo2017-05-24VerifiedExploit-DB 42084Samba 3.5.0 < 4.4.14/4.5.10/4.6.4 - 'is_known_pipename()' Arbitrary Module Load (Metasploit)Metasploit2017-05-29VerifiedPoC-in-GitHub · betab0t/cve-2017-7494Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)★ 181betab0t2017-05-25CandidatePoC-in-GitHub · homjxi0e/CVE-2017-7494★ 0homjxi0e2017-05-25CandidatePoC-in-GitHub · opsxcq/exploit-CVE-2017-7494SambaCry exploit and vulnerable container (CVE-2017-7494)★ 380opsxcq2017-05-26CandidatePoC-in-GitHub · Waffles-2/SambaCryCVE-2017-7494 - Detection Scripts★ 63Waffles-22017-05-26CandidatePoC-in-GitHub · brianwrf/SambaHunterIt is a simple script to exploit RCE for Samba (CVE-2017-7494 ).★ 58brianwrf2017-05-30CandidatePoC-in-GitHub · joxeankoret/CVE-2017-7494Remote root exploit for the SAMBA CVE-2017-7494 vulnerability★ 259joxeankoret2017-06-05CandidatePoC-in-GitHub · Zer0d0y/Samba-CVE-2017-7494搭建漏洞利用测试环境★ 1Zer0d0y2017-07-28CandidatePoC-in-GitHub · incredible1yu/CVE-2017-7494CVE-2017-7494 C poc★ 0incredible1yu2018-05-10CandidatePoC-in-GitHub · cved-sources/cve-2017-7494cve-2017-7494★ 0cved-sources2019-01-06CandidatePoC-in-GitHub · john-80/cve-2017-7494samba 4.5.9★ 0john-802019-12-30CandidatePoC-in-GitHub · Hansindu-M/CVE-2017-7494_IT19115344A remote code execution flaw was found in Samba. A malicious authenticated samba client, having write access to the samba share, could use this flaw to execute arbitrary code as root.★ 0Hansindu-M2020-05-10CandidatePoC-in-GitHub · 0xm4ud/noSAMBAnoCRY-CVE-2017-7494CVE-2017-7494 python exploit★ 60xm4ud2021-05-09CandidatePoC-in-GitHub · I-Rinka/BIT-EternalBlue-for-macOS_LinuxExploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.★ 4I-Rinka2021-05-15CandidatePoC-in-GitHub · adjaliya/-CVE-2017-7494-Samba-Exploit-POCAccording to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable Samba versions, for which there is no fix. The newest Samba models, including the models 4.6.x before 4.6.4, 4.5.x before 4.5.10 and 3.5.0 before 4.4.13, was impacted by this error. May 24, 2017, Samba released version 4.6.4, which fixes a serious remote code execution vulnerability, vulnerability number CVE-2017-7494, which affected Samba 3.5.0 onwards. Vulnerability number: CVE-2017-7494 Severity Rating: High Affected software: • Samba Version < 4.6.4 • Samba Version < 4.5.10 • Samba Version < 4.4.14 Unaffected software: • Samba Version = 4.6.4 • Samba Version = 4.5.10 • Samba Version = 4.4.14★ 0adjaliya2021-09-29CandidatePoC-in-GitHub · 00mjk/exploit-CVE-2017-7494SambaCry exploit (CVE-2017-7494)★ 100mjk2022-05-29CandidatePoC-in-GitHub · d3fudd/CVE-2017-7494_SambaCrySambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit★ 7d3fudd2022-11-01CandidatePoC-in-GitHub · FelipeR-UFBA/cve-2017-7494-fixedCustom Docker Image★ 0FelipeR-UFBA2025-11-22CandidatePoC-in-GitHub · sudlit/CVE-2017-7494★ 0sudlit2025-12-02CandidatePoC-in-GitHub · Zanex360/cdt-samba-deployCDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box★ 0Zanex3602026-02-07CandidatePoC-in-GitHub · Zanex360/cdt-vulnsamba-deployCDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box★ 0Zanex3602026-02-07CandidatePoC-in-GitHub · YonLiud/CVE-2017-7494SambaCry Explanation and Exploitation Demo with POC★ 2YonLiud2026-08-15Candidate