THREAT OPS › Threat News › [NVD] CVE-2025-10230 (CRITICAL 10.0) — A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the
[NVD] CVE-2025-10230 (CRITICAL 10.0) — A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the
CVE-2025-10230 CVSS: 10.0 CRITICAL Published: 2025-11-07T20:15:35.630
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins h
Indicators of compromise
- CVE-2025-10230cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-10230