¡¾Îó²îͨ¸æ¡¿Samba WINS ÏÂÁî×¢ÈëÎó²î(CVE-2025-10230)

Ðû²¼Ê±¼ä 2025-10-16

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Samba WINS ÏÂÁî×¢ÈëÎó²î

CVE   ID

CVE-2025-10230

Îó²îÀàÐÍ

ÏÂÁî×¢Èë

·¢Ã÷ʱ¼ä

2025-10-16

Îó²îÆÀ·Ö

10

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


SambaÊÇÒ»¸ö¿ªÔ´µÄÈí¼þÌ×¼þ£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÔÚUnixºÍLinuxϵͳÓëWindowsϵͳ֮¼ä¹²ÏíÎļþºÍ´òÓ¡×ÊÔ´¡£¡£¡£¡£ËüʵÏÖÁË΢ÈíµÄSMB/CIFSЭÒ飬£¬£¬£¬£¬Ê¹µÃ·ÇWindowsϵͳÄܹ»ÓëWindowsÍøÂçÇéÐμæÈÝ£¬£¬£¬£¬£¬ÌṩÎļþ¹²Ïí¡¢´òÓ¡»ú¹²ÏíÒÔ¼°Óò¿ØÖƵȹ¦Ð§¡£¡£¡£¡£Samba¿É×÷ΪÓò¿ØÖÆÆ÷»ò³ÉԱЧÀÍÆ÷ÔËÐУ¬£¬£¬£¬£¬Ö§³ÖÓëWindows Active Directory¼¯³É£¬£¬£¬£¬£¬ÌṩÓû§ÈÏÖ¤ºÍȨÏÞÖÎÀí¡£¡£¡£¡£ÓÉÓÚÆä¸ß¼æÈÝÐԺͿª·ÅÔ´´úÂ룬£¬£¬£¬£¬SambaÆÕ±éÓ¦ÓÃÓÚ¿çÆ½Ì¨µÄÆóÒµÍøÂçÇéÐÎÖС£¡£¡£¡£


2025Äê10ÔÂ16ÈÕ£¬£¬£¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½Ò»¸ö±£´æÓÚSambaÖеÄÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÆôÓÃÁËWINSЧÀÍÆ÷µÄSambaÓò¿ØÖÆÆ÷¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬µ±SambaÉèÖÃÁËwins hook²ÎÊý£¬£¬£¬£¬£¬²¢ÇÒWINSÖ§³Ö±»ÆôÓÃʱ£¬£¬£¬£¬£¬SambaÔÚWINSÃû³Æ±ä»»Ê±»áÖ´ÐиòÎÊýÖ¸¶¨µÄ³ÌÐò¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Sambaδ¶Ôת´ï¸øwins hook³ÌÐòµÄÃû³Æ¾ÙÐÐÓÐÓÃÑéÖ¤£¬£¬£¬£¬£¬µ¼Ö¿ÉÒÔͨ¹ý²åÈë°üÀ¨shellÔª×Ö·ûµÄÃû³ÆÀ´Ö´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬´Ó¶øÊµÏÖδ¾­ÈÏÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£Îó²îÆÀ·Ö10·Ö£¨ÒÀ¾ÝSamba¹Ù·½Í¨¸æ£©£¬£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Samba < 4.23.2
Samba < 4.22.5
Samba < 4.21.9


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Samba¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£
Samba >= 4.23.2
Samba >= 4.22.5
Samba >= 4.21.9


ÏÂÔØÁ´½Ó£ºhttps://www.samba.org/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.samba.org/samba/security/CVE-2025-10230.html/