CVE-2007-2447
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving...
- Published
- May 14, 2007
- Updated
- Nov 4, 2025
- Assigning CNA
- redhat
- Evidence observed
- Aug 18, 2010
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:PModerate · next 30 days
- Percentile
- 98.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.
Sources
37- CVE-2007-2447Exploit
Python exploit for Samba CVE-2007-2447 username map script remote command execution, delivering a reverse shell payload to a configurable remote listener.
- CVE-2007-2447Exploit
Python exploit for CVE-2007-2447 that triggers Samba username map script command injection to open a reverse shell on vulnerable targets.
Proof-of-concept exploit for Samba usermap script remote command execution (CVE-2007-2447), with reverse shell capability for controlled lab testing and security research.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.