¡¾¸´ÏÖ¡¿Samba ÈÏ֤ǰÏÂÁî×¢ÈëÎó²î£¨CVE-2025-10230 £©

Ðû²¼Ê±¼ä 2025-10-29

¿ËÈÕ£¬£¬£¬£¬SambaÍŶÓÐû²¼ÁËÒ»·Ý½ôÆÈÇ徲ͨ¸æ£¬£¬£¬£¬Ö¼ÔÚ½â¾öÁ½¸öÎó²î¡£¡£¡£ÆäÖаüÀ¨Ò»¸öÑÏÖØµÄÈÏ֤ǰÏÂÁî×¢ÈëÎó²î£¨CVE-2025-10230£©£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÎÞÐèÈÏÖ¤µÄÌõ¼þ϶ÔSamba Active DirectoryÓò¿ØÖÆÆ÷ (AD DC) Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ×î¸ß10.0£¬£¬£¬£¬¿ÉÓ°ÏìÆôÓÃÁËWINSÖ§³ÖÇÒÉèÖÃÁËwins hook²ÎÊýµÄϵͳ¡£¡£¡£


Ó°Ïì°æ±¾


Samba 4.0¼°Ö®ºóËùÓа汾£¨·ÇÓò¿Ø²»ÊÜÓ°Ï죩


Îó²î³ÉÒò


./source4/nbt_server/wins/wins_hook.c ÎļþÖеĠwins_hook º¯ÊýÀ£¬£¬£¬»á½«ÎüÊÕµ½µÄNetBIOSÃû³Æ×Ö·û´®rec->name->nameÆ´½Óµ½cmd×Ö·û´®ÖС£¡£¡£



ͼƬ1.png


ÔÚºóÐøµÄ´úÂë´¦Öóͷ£ÖУ¬£¬£¬£¬cmd×Ö·û´®½«ÓÃÓÚÏÂÁîÖ´ÐС£¡£¡£Í¬Ê±£¬£¬£¬£¬ÕâÀï¶ÔNetBIOSÊý¾ÝÎüÊÕûÓÐ×öÈκμøÈ¨ºÍ¼ì²é£¬£¬£¬£¬´Ó¶øÔì³ÉÈÏ֤ǰµÄÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£


Îó²î¸´ÏÖ


ÒÔ½¨ÉèÎļþ¼ÐÏÂÁîΪÀý¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬ÎÞÐèÈÏÖ¤¼´¿É·¢ËͶñÒâµÄ±¨ÎÄ£º


ͼƬ2.png


È»ºó£¬£¬£¬£¬ÔÚADЧÀÍÆ÷ÉÏ·¢Ã÷Îļþ¼Ð123±»Àֳɽ¨ÉèÁË¡£¡£¡£


ͼƬ3.png


ÐÞ¸´½¨Òé


£¨1£©·½·¨Ò»£ºÔÚSamba ADÓò¿ØÖÆÆ÷µÄsmb.confÖУ¬£¬£¬£¬ÈçϽûÓÃwins support¡£¡£¡£


ͼƬ4.png


£¨2£©·½·¨¶þ£ºÔÚSamba ADÓò¿ØÖÆÆ÷µÄsmb.confÖУ¬£¬£¬£¬ÈçϽûÓòÎÊýwins hook¡£¡£¡£


ͼƬ5.png



²Î¿¼Á´½Ó£º

[1]https://www.samba.org/samba/security/CVE-2025-10230.html



c7c7ÓéÀÖÆ½Ì¨Æð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î6500Óà¸ö£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢AI+Çå¾²Ñо¿¡¢ÎÀÐÇÇå¾²Ñо¿¡¢ÔËÓªÉÌ»ù´¡ÉèÊ©Çå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·À¶Ô¿¹ÊÖÒÕÑо¿¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵È¡£¡£¡£


adlab.jpg