The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit auxiliary module (modules/auxiliary/admin/smb/samba_symlink_traversal.rb) that exploits a directory traversal vulnerability (CVE-2010-0926) in the Samba CIFS server. The exploit requires access to a writeable SMB share on the target server. When executed, it creates a symlink within the share that points to the root filesystem ('/'), allowing an attacker to traverse outside the share and potentially access sensitive files. The module is written in Ruby and leverages Metasploit's SMB client mixins. The main entry point is the 'run' method, which handles connecting to the server, authenticating, mounting the share, creating the symlink, and informing the user how to access the root filesystem via the SMB share. No custom payload is delivered; the exploit's effect is to enable directory traversal through the SMB share.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.