¡¾¸´ÏÖ¡¿Samba ÈÏ֤ǰÏÂÁî×¢ÈëÎó²î£¨CVE-2025-10230 £©
Ðû²¼Ê±¼ä 2025-10-29¿ËÈÕ£¬£¬£¬£¬SambaÍŶÓÐû²¼ÁËÒ»·Ý½ôÆÈÇ徲ͨ¸æ£¬£¬£¬£¬Ö¼ÔÚ½â¾öÁ½¸öÎó²î¡£¡£ÆäÖаüÀ¨Ò»¸öÑÏÖØµÄÈÏ֤ǰÏÂÁî×¢ÈëÎó²î£¨CVE-2025-10230£©£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÎÞÐèÈÏÖ¤µÄÌõ¼þ϶ÔSamba Active DirectoryÓò¿ØÖÆÆ÷ (AD DC) Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ×î¸ß10.0£¬£¬£¬£¬¿ÉÓ°ÏìÆôÓÃÁËWINSÖ§³ÖÇÒÉèÖÃÁËwins hook²ÎÊýµÄϵͳ¡£¡£
Ó°Ïì°æ±¾
Îó²î³ÉÒò
./source4/nbt_server/wins/wins_hook.c ÎļþÖÐµÄ wins_hook º¯ÊýÀ£¬£¬£¬»á½«ÎüÊÕµ½µÄNetBIOSÃû³Æ×Ö·û´®rec->name->nameÆ´½Óµ½cmd×Ö·û´®ÖС£¡£

ÔÚºóÐøµÄ´úÂë´¦Öóͷ£ÖУ¬£¬£¬£¬cmd×Ö·û´®½«ÓÃÓÚÏÂÁîÖ´ÐС£¡£Í¬Ê±£¬£¬£¬£¬ÕâÀï¶ÔNetBIOSÊý¾ÝÎüÊÕûÓÐ×öÈκμøÈ¨ºÍ¼ì²é£¬£¬£¬£¬´Ó¶øÔì³ÉÈÏ֤ǰµÄÏÂÁîÖ´ÐÐÎó²î¡£¡£
Îó²î¸´ÏÖ
ÒÔ½¨ÉèÎļþ¼ÐÏÂÁîΪÀý¡£¡£Ê×ÏÈ£¬£¬£¬£¬ÎÞÐèÈÏÖ¤¼´¿É·¢ËͶñÒâµÄ±¨ÎÄ£º

È»ºó£¬£¬£¬£¬ÔÚADЧÀÍÆ÷ÉÏ·¢Ã÷Îļþ¼Ð123±»Àֳɽ¨ÉèÁË¡£¡£

ÐÞ¸´½¨Òé
£¨1£©·½·¨Ò»£ºÔÚSamba ADÓò¿ØÖÆÆ÷µÄsmb.confÖУ¬£¬£¬£¬ÈçϽûÓÃwins support¡£¡£

£¨2£©·½·¨¶þ£ºÔÚSamba ADÓò¿ØÖÆÆ÷µÄsmb.confÖУ¬£¬£¬£¬ÈçϽûÓòÎÊýwins hook¡£¡£

[1]https://www.samba.org/samba/security/CVE-2025-10230.html
ÄϹ¬NGÓéÀÖÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î6500Óà¸ö£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢AI+Çå¾²Ñо¿¡¢ÎÀÐÇÇå¾²Ñо¿¡¢ÔËÓªÉÌ»ù´¡ÉèÊ©Çå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·À¶Ô¿¹ÊÖÒÕÑо¿¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵ȡ£¡£



¾©¹«Íø°²±¸11010802024551ºÅ