CVE-2025-66003
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-66003 is an External Control of File Name or Path (CWE-73) vulnerability in smb4k, a KDE-based SMB/Samba share browser for Linux. It allows local users to perform a local privilege escalation to root via the smb4k_mounthelper component if they can access and control the contents of a Samba share. All versions of smb4k prior to 4.0.5 are affected. The vulnerability was disclosed by SUSE on December 10, 2025, and published to NVD on January 8, 2026. It carries a CVSS v4.0 base score of 7.3 (High), assigned by SUSE as the CNA (SUSE Advisory, SUSE Bugzilla).

Technical details

The root cause is classified as CWE-73 (External Control of File Name or Path), where smb4k's smb4k_mounthelper — a privileged KAuth helper that runs with elevated permissions — does not sufficiently validate or sanitize file name or path inputs derived from Samba share contents. An attacker who can control the contents of a Samba share (e.g., by hosting a malicious share or manipulating share metadata) can supply crafted path values that the mounthelper processes with root privileges, enabling privilege escalation. The attack vector is local (AV:L), requires low privileges (PR:L), has high attack complexity (AC:H), and no user interaction, meaning the attacker must have local system access and the ability to influence a Samba share that the victim mounts (SUSE Advisory, SUSE Bugzilla).

Impact

Successful exploitation grants a local attacker full root-level access on the affected Linux system, resulting in complete compromise of confidentiality, integrity, and availability of the host. An attacker achieving root can read all sensitive files, modify system configurations, install persistent backdoors, and pivot to other systems on the network. The impact is confined to the vulnerable host (no lateral sub-system impact is scored), but root access effectively removes all OS-level security boundaries (SUSE Advisory).

Exploitability

A proof-of-concept reference has been noted in public sources, including a blog post describing the exploit mechanism (PoC Blog). The vulnerability is detected by both Nessus (plugin 281598) and Qualys (ID 6272502), indicating active scanner coverage. The EPSS score is approximately 0.016% (0.000160), reflecting a currently low probability of widespread exploitation. There is no evidence of in-the-wild exploitation by named threat actors, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report (Tenable Nessus, CIRCL).

Exploitation steps

  1. Reconnaissance: Identify a target Linux system running smb4k version prior to 4.0.5 with the KAuth helper (smb4k_mounthelper) installed and accessible.
  2. Gain local access: Obtain a low-privileged local user account on the target system (e.g., via phishing, credential theft, or another vulnerability).
  3. Set up or control a Samba share: Either host a malicious Samba share or gain control over the contents/metadata of an existing Samba share that the target system is configured to mount via smb4k.
  4. Craft malicious share content: Embed specially crafted file names or path values within the Samba share that exploit the insufficient input validation in smb4k_mounthelper (e.g., path traversal sequences or specially encoded filenames that redirect privileged file operations).
  5. Trigger mount operation: Cause smb4k to mount the malicious share, which invokes smb4k_mounthelper with elevated (root) privileges and processes the attacker-controlled path values.
  6. Achieve root execution: The mounthelper processes the malicious path with root privileges, enabling the attacker to write to arbitrary system locations, execute commands as root, or otherwise escalate to full system compromise (SUSE Advisory, PoC Blog).

Indicators of compromise

  • Process: Unexpected child processes spawned by smb4k_mounthelper running as root (e.g., /bin/bash, sh, python, perl, or network tools like curl/wget); smb4k_mounthelper invoked with unusual or malformed path arguments visible in process audit logs.
  • Logs: Audit log (/var/log/audit/audit.log) entries showing smb4k_mounthelper accessing or writing to unexpected filesystem paths outside of standard mount points; KAuth/polkit logs showing elevated privilege grants to smb4k for unusual operations.
  • File System: New or modified files in sensitive directories (e.g., /etc/passwd, /etc/sudoers, /root/.ssh/authorized_keys, cron directories) with timestamps correlating to smb4k mount activity; unexpected SUID/SGID binaries created after a mount event.
  • Network: Outbound connections from the smb4k host to unknown external IPs shortly after a Samba share mount event; connections to Samba shares from unusual or untrusted hosts.

Mitigation and workarounds

Users should upgrade smb4k to version 4.0.5 or later, which addresses this vulnerability. Debian has issued DSA-6092-1 covering smb4k, and Fedora has released updated packages; users on these distributions should apply the available security updates promptly. As a workaround where upgrading is not immediately possible, administrators should restrict which Samba shares users are permitted to mount via smb4k, avoid mounting shares from untrusted sources, and consider removing or restricting the smb4k_mounthelper KAuth helper permissions until patching is feasible (SUSE Advisory, Linux Security Debian).

Community reactions

SUSE's security team published a detailed advisory on December 10, 2025, describing the issues as "major" in the KAuth helper component, prompting downstream distributions including Debian and Fedora to issue security updates (SUSE Advisory). The vulnerability was discussed on the oss-security mailing list shortly after disclosure (oss-sec). Community discussion on Bluesky noted the local privilege escalation risk, though overall social media attention has been limited given the local-only attack vector and niche software affected.

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management