Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

CVE-2007-2446

Published
May 14, 2007
Updated
Apr 10, 2026
Affected
0 pkgs
Patched
None yet
Exploits
9 known

EPSS Exploitation Probability

via FIRST.org ↗
90.1%probability of exploitation in next 30 days
Very High Risk100th percentile+1.08%
88.4%89.1%89.9%90.6%88.9%90.1%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).

Exploits & PoCs
9

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-16875remoteosx✓ Verified

Samba 3.0.10 (OSX) - 'lsa_io_trans_names' Heap Overflow (Metasploit)

by Metasploit · Apr 5, 2010

EDB-9950remotelinux✓ Verified

Samba 3.0.21 < 3.0.24 - LSA trans names Heap Overflow (Metasploit)

by Adriano Lima · May 14, 2007

EDB-16329remotesolaris✓ Verified

Samba 3.0.24 (Solaris) - 'lsa_io_trans_names' Heap Overflow (Metasploit)

by Metasploit · Apr 5, 2010

EDB-16859remotelinux✓ Verified

Samba 3.0.24 (Linux) - 'lsa_io_trans_names' Heap Overflow (Metasploit)

by Metasploit · Jul 14, 2010

Frequently Asked Questions

Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
O3 Security · Impact-Aware SCA

Is CVE-2007-2446 in your stack?

O3 detects CVE-2007-2446 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.