CVE-2010-0728
Estado: ModificadaAlta (8.5)—
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C
- Puntuación base: 8.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.81%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://lists.samba.org/archive/samba-announce/2010/000211.html
- http://www.samba.org/samba/history/samba-3.3.12.html
- http://www.samba.org/samba/history/samba-3.4.7.html
- http://www.samba.org/samba/history/samba-3.5.1.html
- http://www.samba.org/samba/security/CVE-2010-0728
- https://bugzilla.samba.org/show_bug.cgi?id=7222
- http://lists.samba.org/archive/samba-announce/2010/000211.html
- http://www.samba.org/samba/history/samba-3.3.12.html
- http://www.samba.org/samba/history/samba-3.4.7.html
- http://www.samba.org/samba/history/samba-3.5.1.html
- http://www.samba.org/samba/security/CVE-2010-0728
- https://bugzilla.samba.org/show_bug.cgi?id=7222
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-0728",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 8.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-03-10T20:13:03.777",
"references": [
{
"url": "http://lists.samba.org/archive/samba-announce/2010/000211.html",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.samba.org/samba/history/samba-3.3.12.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.samba.org/samba/history/samba-3.4.7.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.samba.org/samba/history/samba-3.5.1.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.samba.org/samba/security/CVE-2010-0728",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.samba.org/show_bug.cgi?id=7222",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.samba.org/archive/samba-announce/2010/000211.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.samba.org/samba/history/samba-3.3.12.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.samba.org/samba/history/samba-3.4.7.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.samba.org/samba/history/samba-3.5.1.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.samba.org/samba/security/CVE-2010-0728",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.samba.org/show_bug.cgi?id=7222",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client."
},
{
"lang": "es",
"value": "smbd en Samba v3.3.11, v3.4.6, y v3.5.0, cuando el soporte libcap está activado, se ejecuta con la capacidad CAP_DAC_OVERRIDE, lo que permite a usuarios autenticados remotamente superar los permisos establecidos de archivos establecidos a través de operaciones filesystem con cualquier cliente."
}
],
"lastModified": "2026-06-16T23:16:43.953",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samba:samba:3.3.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "254D9460-899D-4D06-AC47-1914A42FC09A"
},
{
"criteria": "cpe:2.3:a:samba:samba:3.4.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FC5E48D-95CC-46E9-9491-CA8A5FD9F14E"
},
{
"criteria": "cpe:2.3:a:samba:samba:3.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5900E6E-4379-4321-B69D-F9FBD341ACEC"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Not vulnerable.\n\nThis issue did not affect the versions of the samba package, as shipped with Red Hat Enterprise Linux 3, 4, or 5.\n\nThis issue did not affect the version of the samba3x package, as shipped with Red Hat Enterprise Linux 5.",
"lastModified": "2010-03-12T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "secalert@redhat.com"
}