CVE-2007-2447Exploit(samba / samba)

LOWCVSS 6.0 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for samba samba systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

3.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • samba

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
samba

37 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-07-11: 1PoC Mentioned / Linked · 2026-07-11: 1Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-07-11: 1Technical Details · 2026-07-11: 104-1407-11
Signal classification1 categories
Exploit
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Bla_Ze 🔥🔥@KuveY81945
    Exploit

    Just pwned Lame on HackTheBox! 🎯 Exploited Samba 3.0.20 via CVE-2007-2447 using Metasploit. Got root! 🔥 https://labs.hackthebox.com/achievement/machine/3216229/1 #HackTheBox #HackTheBoxOndo #HTB #CyberSecurity #EthicalHacking #InfoSec #PenTesting

    Post summary

    The user demonstrates a successful exploitation of Samba 3.0.20 via CVE-2007-2447 on HackTheBox using Metasploit, achieving root access, with no mention of patches or real-world attacks.

    0002033
    14 followersView on X
  • elc0ket@whoami_elc0ket
    Exploit

    Writeup: Vulnerability de http://whoami-labs.com ¡Pwned! Samba 3.0.20 vulnerable a CVE-2007-2447 → RCE sin auth → shell de root (Metasploit + exploit manual). Writeup completo 👇 https://github.com/elc0ket/ctf-writeups/ #CTF #HackingEtico #Samba #CVE20072447

    Post summary

    The post indicates a Metasploit module and manual exist for the Samba 3.0.20 CVE‑2007‑2447, confirming exploitable RCE and root shell, but it does not report active exploitation or provide a patch.

    0000066
    21 followersView on X
CPE platform detail42 entries

42 of 42 entries

PartVendorProductVersionTarget SWTarget HW
Appsambasamba3.0.0--
Appsambasamba3.0.1--
Appsambasamba3.0.10--
Appsambasamba3.0.11--
Appsambasamba3.0.12--
Appsambasamba3.0.13--
Appsambasamba3.0.14--
Appsambasamba3.0.14a--
Appsambasamba3.0.15--
Appsambasamba3.0.16--
Appsambasamba3.0.17--
Appsambasamba3.0.18--
Appsambasamba3.0.19--
Appsambasamba3.0.2--
Appsambasamba3.0.20--
Appsambasamba3.0.20a--
Appsambasamba3.0.20b--
Appsambasamba3.0.21--
Appsambasamba3.0.21a--
Appsambasamba3.0.21b--
Appsambasamba3.0.21c--
Appsambasamba3.0.22--
Appsambasamba3.0.23--
Appsambasamba3.0.23a--
Appsambasamba3.0.23b--
Appsambasamba3.0.23c--
Appsambasamba3.0.23d--
Appsambasamba3.0.24--
Appsambasamba3.0.25--
Appsambasamba3.0.25--
Appsambasamba3.0.25--
Appsambasamba3.0.25--
Appsambasamba3.0.25--
Appsambasamba3.0.2a--
Appsambasamba3.0.3--
Appsambasamba3.0.4--
Appsambasamba3.0.4--
Appsambasamba3.0.5--
Appsambasamba3.0.6--
Appsambasamba3.0.7--
Appsambasamba3.0.8--
Appsambasamba3.0.9--

Explore more