We found results for “”
CVE-2025-10230
Good to know:
Date: November 7, 2025
Samba AD DC WINS hook command injection. If the 'wins hook' parameter is set on a domain controller with the WINS server enabled, unauthenticated remote code execution is possible
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78Top Fix
Upgrade Version
Upgrade to version https://github.com/samba-team/samba.git - samba-4.23.2;https://github.com/samba-team/samba.git - samba-4.22.5;https://github.com/samba-team/samba.git - samba-4.21.9
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


