¡¾¸´ÏÖ¡¿Samba ÈÏ֤ǰºÅÁî×¢Èë·ì϶£¨CVE-2025-10230 £©

°ä²¼¹¦·ò 2025-10-29

½üÈÕ£¬£¬£¬SambaÍŶӰ䲼ÁËÒ»·Ý´¹Î£°²È«²¼¸æ£¬£¬£¬Ö¼ÔÚ½â¾öÁ½¸ö·ì϶¡£¡£¡£ÆäÖÐÔ̺¬Ò»¸öÑÏÖØµÄÈÏ֤ǰºÅÁî×¢Èë·ì϶£¨CVE-2025-10230£©£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÎÞÐèÈÏÖ¤µÄǰÌá϶ÔSamba Active DirectoryÓò½ÚÖÆÆ÷ (AD DC) Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ×î¸ß10.0£¬£¬£¬¿ÉÓ°ÏìÆôÓÃÁËWINSÖ§³ÖÇÒÉèÖÃÁËwins hook²ÎÊýµÄϵͳ¡£¡£¡£


Ó°Ïì°æ±¾


Samba 4.0¼°Ö®ºóËùÓа汾£¨·ÇÓò¿Ø²»ÊÜÓ°Ï죩


·ì϶³ÉÒò


./source4/nbt_server/wins/wins_hook.c ÎļþÖеĠwins_hook º¯ÊýÀ£¬£¬»á½«½Ó¹Üµ½µÄNetBIOSÃû³Æ×Ö·û´®rec->name->nameÆ´½Óµ½cmd×Ö·û´®ÖС£¡£¡£



ͼƬ1.png


ÔÚºóÐøµÄ´úÂë´¦ÖÃÖУ¬£¬£¬cmd×Ö·û´®½«ÓÃÓÚºÅÁîÖ´ÐС£¡£¡£Í¬Ê±£¬£¬£¬ÕâÀï¶ÔNetBIOSÊý¾Ý½Ó¹ÜûÓÐ×öÈκμøÈ¨ºÍ²é³­£¬£¬£¬´Ó¶øÔì³ÉÈÏ֤ǰµÄºÅÁîÖ´Ðзì϶¡£¡£¡£


·ì϶¸´ÏÖ


ÒÔ´´½¨Îļþ¼ÐºÅÁîΪÀý¡£¡£¡£Ê×ÏÈ£¬£¬£¬ÎÞÐèÈÏÖ¤¼´¿É·¢ËͶñÒâµÄ±¨ÎÄ£º£º£º


ͼƬ2.png


¶øºó£¬£¬£¬ÔÚAD·þÎñÆ÷ÉÏ·¢ÏÖÎļþ¼Ð123±»³É¹¦´´½¨ÁË¡£¡£¡£


ͼƬ3.png


ÐÞ¸´½¨Òé


£¨1£©·½Ê½Ò»£º£º£ºÔÚSamba ADÓò½ÚÖÆÆ÷µÄsmb.confÖУ¬£¬£¬ÈçϽûÓÃwins support¡£¡£¡£


ͼƬ4.png


£¨2£©·½Ê½¶þ£º£º£ºÔÚSamba ADÓò½ÚÖÆÆ÷µÄsmb.confÖУ¬£¬£¬ÈçϽûÓòÎÊýwins hook¡£¡£¡£


ͼƬ5.png



²Î¿¼Á´½Ó£º£º£º

[1]https://www.samba.org/samba/security/CVE-2025-10230.html



OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£¡£½ØÖÁĿǰ£¬£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶6500Óà¸ö£¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑС¢Êý¾Ý°²È«×êÑС¢5G°²È«×êÑС¢AI+°²È«×êÑС¢ÎÀÐǰ²È«×êÑС¢ÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑС¢Òƶ¯°²È«×êÑС¢ÎïÁªÍø°²È«×êÑС¢³µÁªÍø°²È«×êÑС¢¹¤¿Ø°²È«×êÑС¢ÐÅ´´°²È«×êÑС¢Ôư²È«×êÑС¢ÎÞÏß°²È«×êÑС¢¸ß¼¶Íþв×êÑС¢¹¥·ÀÆ¥µÐ¼¼Êõ×êÑС£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£


adlab.jpg