CVE-2025-10230
Samba WINS Hook Command Injection Leading to Remote Code Execution
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
A vulnerability in Samba's WINS hook handling allows remote command execution as the Samba process via unsanitized NetBIOS names in registration packets. This could impact the integrity and availability of the domain controller and its services. Confirm if your environment uses this Samba functionality and is exposed.