4.4
CVSSv2

CVE-2010-0787

Published: 02/03/2010 Updated: 07/11/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 3.2.3

samba samba 3.4.0

samba samba 3.4.5

samba samba 3.0.28a

samba samba 3.0.22

Vendor Advisories

Ronald Volgers discovered that the mountcifs utility, when installed as a setuid program, suffered from a race condition when verifying user permissions A local attacker could trick samba into mounting over arbitrary locations, leading to a root privilege escalation ...