CVE-2017-12163
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.1epss 7.6%
exploitation probability
7.6%top 6% of all CVEs
observed exploitation
nono source reports it
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
CVSS:3.0/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected products
Samba · SambaReferences
https://access.redhat.com/errata/RHSA-2017:2789https://access.redhat.com/errata/RHSA-2017:2790https://access.redhat.com/errata/RHSA-2017:2791https://access.redhat.com/errata/RHSA-2017:2858https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12163https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_ushttps://security.netapp.com/advisory/ntap-20170921-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_ushttps://www.debian.org/security/2017/dsa-3983https://www.samba.org/samba/security/CVE-2017-12163.htmlhttps://www.synology.com/support/security/Synology_SA_17_57_Sambahttp://www.securityfocus.com/bid/100925