CVE-2003-0201 is a remotely exploitable buffer overflow in the call_trans2open function in Samba's trans2.c. It affects Samba 2.2.x before 2.2.8a, Samba 2.0.10 and earlier 2.0.x releases, and Samba-TNG before 0.3.2. A remote, unauthenticated attacker can send crafted SMB/CIFS requests that trigger memory corruption in the Trans2 open handling path, leading to process compromise and arbitrary code execution. Because the vulnerable service commonly runs with elevated privileges, successful exploitation can result in full host compromise. The issue was also associated with exploit tooling targeting Samba 3.0.x in later offensive archives, but the specific CVE description provided identifies the vulnerable function and affected versions listed above.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (11 hidden).
This repository contains a single Metasploit exploit module targeting a buffer overflow vulnerability in Samba versions 2.2.0 to 2.2.8 on Linux x86 systems (CVE-2003-0201, also known as ECHOWRECKER). The exploit works by sending a specially crafted SMB trans2open request to the target's SMB service (default port 139), overflowing a buffer and allowing arbitrary code execution. The module supports brute-forcing the return address to improve reliability across different Linux distributions. The payload is customizable and typically results in a shell on the target system. The exploit requires the target to have a vulnerable Samba version and the SMB service accessible. The code is written in Ruby and is designed to be used within the Metasploit framework.
This repository contains a single Metasploit module: 'modules/exploits/solaris/samba/trans2open.rb'. The module exploits a buffer overflow vulnerability (CVE-2003-0201) in Samba versions 2.2.0 to 2.2.8 running on Solaris SPARC systems. The exploit targets the SMB service (typically on TCP port 139) and is capable of brute-forcing return addresses to achieve reliable code execution. The payload is customizable and leverages Metasploit's payload generation capabilities, allowing the attacker to execute arbitrary code (such as a shell) on the target system. The exploit is weaponized, as it is part of the Metasploit framework and supports automated payload delivery and brute-forcing. The file is written in Ruby and is structured according to Metasploit's exploit module conventions, including target definitions, payload configuration, and network interaction logic. No hardcoded IP addresses, URLs, or file paths are present, but the exploit is fingerprintable by its use of SMB on port 139 and its targeting of specific vulnerable Samba/Solaris versions.
This repository contains a single Metasploit exploit module targeting a buffer overflow vulnerability (CVE-2003-0201) in Samba versions 2.2.0 to 2.2.8 running on Mac OS X PowerPC systems. The exploit works by sending a specially crafted SMB trans2open request to the target's SMB service (default port 139), overflowing a buffer and allowing arbitrary code execution. The module supports brute-forcing the return address due to stack address randomization on the target platform. The payload is customizable and is injected into the overflowed buffer, enabling the attacker to execute code of their choice (commonly a shell). The exploit requires the target to be accessible over the network and running a vulnerable version of Samba. The code is written in Ruby and is designed to be used within the Metasploit framework. The repository structure is minimal, containing only the exploit module file.
This repository contains a single Metasploit exploit module targeting a buffer overflow vulnerability in Samba versions 2.2.0 to 2.2.8 on FreeBSD x86 systems (CVE-2003-0201). The exploit leverages the 'trans2open' SMB request to overflow a buffer and execute arbitrary code. The module is written in Ruby and is structured according to Metasploit conventions, including payload selection, brute-forcing of return addresses, and SMB client interaction. The exploit requires the target to be running a vulnerable version of Samba on TCP port 139 and does not have the 'noexec' stack option enabled. The payload is customizable and can provide a shell or other code execution on the target. The module is operational and suitable for use in penetration testing or red teaming against appropriately configured targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.