CVE-2007-2446 is a set of multiple heap-based buffer overflow vulnerabilities in Samba’s smbd MS-RPC NDR parsing code affecting Samba 3.0.0 through 3.0.25rc3. Remote attackers can trigger memory corruption via crafted MS-RPC requests to specific RPC operations/paths including DFSEnum (netdfs_io_dfs_EnumInfo_d), RFNPCNEX (smb_io_notify_option_type_data), LsarAddPrivilegesToAccount (lsa_io_privilege_set), NetSetFileSecurity (sec_io_acl), and LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names). Successful exploitation can lead to arbitrary code execution in the context of the smbd process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module targeting a heap overflow vulnerability (CVE-2007-2446) in the LSA RPC service of the Samba daemon. The exploit is implemented in Ruby and leverages the Metasploit framework's SMB and DCERPC client libraries. The module connects to a remote Samba server over SMB, binds to the LSARPC named pipe, and sends a specially crafted request to the LsarAddPrivilegesToAccount function, triggering a heap overflow and causing a denial of service (service crash). The module is a proof-of-concept denial-of-service exploit and does not provide code execution or a customizable payload. The only required endpoint is the LSARPC named pipe, and the exploit targets Samba installations vulnerable to CVE-2007-2446. The repository structure is typical for a Metasploit module, with all logic contained in a single Ruby file.
This repository contains a single Metasploit exploit module targeting a heap overflow vulnerability (CVE-2007-2446) in the LSA RPC service of Samba running on Solaris 8, 9, or 10 (x86 and SPARC architectures), specifically for Samba versions 3.0.21 through 3.0.24. The exploit leverages a TALLOC chunk overwrite technique to achieve remote code execution via the LSARPC named pipe over SMB. The module supports brute-forcing return addresses for both x86 and SPARC targets and allows the user to specify the SMB named pipe (default: LSARPC). The payload is customizable and can be any Metasploit payload up to 1024 bytes. The exploit requires the Samba 'log level' to be 2 or lower and will not work if the service is patched. The code is written in Ruby and is structured as a standard Metasploit module, including all necessary options and target definitions. The main attack vector is network-based, exploiting the DCERPC service over SMB. The module is operational and suitable for use in penetration testing scenarios where the target configuration matches the requirements.
This repository contains a single Metasploit exploit module targeting a heap overflow vulnerability (CVE-2007-2446) in the LSA RPC service of the Samba daemon on Linux systems. The exploit leverages a TALLOC chunk overwrite technique to achieve remote code execution as root. It is effective against Samba versions 3.0.21 through 3.0.24, provided the 'log level' is set to 2 or lower. The module supports brute-forcing heap addresses for various Linux distributions and architectures (x86, MIPS). The exploit communicates with the target over SMB, specifically using the LSARPC named pipe and the LSA DCERPC interface (UUID 12345778-1234-abcd-ef00-0123456789ab). The payload is customizable via Metasploit and can provide a shell or other post-exploitation capabilities. The code is mature and operational, with options for brute-forcing and multiple target profiles, and is intended for use within the Metasploit framework.
This repository contains a single Metasploit auxiliary module targeting a heap overflow vulnerability (CVE-2007-2446) in the LSA RPC service of Samba. The exploit is implemented in Ruby and leverages the Metasploit framework's SMB and DCERPC libraries. The module connects to a remote Samba server over SMB, binds to the LSARPC named pipe using the LSA RPC interface UUID, and sends a specially crafted request to trigger a heap overflow, resulting in a denial of service (service crash). The module does not provide a shell or code execution, but is designed to crash the target service. The only fingerprintable endpoints are the LSARPC named pipe and the LSA RPC interface UUID. The code is operational and can be used to test or demonstrate the vulnerability on affected Samba installations.
This repository contains a single Metasploit exploit module targeting a heap overflow vulnerability (CVE-2007-2446) in the LSA RPC service of Samba 3.0.10 running on Mac OS X 10.4.x (both x86 and PPC architectures). The exploit leverages a crafted DCERPC request over the SMB protocol to the LSARPC named pipe, triggering a heap overflow via the lsa_io_trans_names function. The module supports brute-forcing return addresses for both x86 and PPC targets and allows the user to select a Metasploit payload, which will be executed with the privileges of the Samba daemon if exploitation is successful. The code is written in Ruby and is structured as a standard Metasploit module, making use of Metasploit's SMB and DCERPC libraries. The main fingerprintable endpoints are the LSARPC named pipe and the DCERPC UUID for the LSA service. The exploit is operational and can be used to achieve remote code execution on vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.