THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-10230 (CRITICAL 10.0) — A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the

[NVD] CVE-2025-10230 (CRITICAL 10.0) — A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the

lownvdPublished 2025-11-07

CVE-2025-10230 CVSS: 10.0 CRITICAL Published: 2025-11-07T20:15:35.630

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins h

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-10230