
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66003 is an External Control of File Name or Path (CWE-73) vulnerability in smb4k, a KDE-based SMB/Samba share browser for Linux. It allows local users to perform a local privilege escalation to root via the smb4k_mounthelper component if they can access and control the contents of a Samba share. All versions of smb4k prior to 4.0.5 are affected. The vulnerability was disclosed by SUSE on December 10, 2025, and published to NVD on January 8, 2026. It carries a CVSS v4.0 base score of 7.3 (High), assigned by SUSE as the CNA (SUSE Advisory, SUSE Bugzilla).
The root cause is classified as CWE-73 (External Control of File Name or Path), where smb4k's smb4k_mounthelper — a privileged KAuth helper that runs with elevated permissions — does not sufficiently validate or sanitize file name or path inputs derived from Samba share contents. An attacker who can control the contents of a Samba share (e.g., by hosting a malicious share or manipulating share metadata) can supply crafted path values that the mounthelper processes with root privileges, enabling privilege escalation. The attack vector is local (AV:L), requires low privileges (PR:L), has high attack complexity (AC:H), and no user interaction, meaning the attacker must have local system access and the ability to influence a Samba share that the victim mounts (SUSE Advisory, SUSE Bugzilla).
Successful exploitation grants a local attacker full root-level access on the affected Linux system, resulting in complete compromise of confidentiality, integrity, and availability of the host. An attacker achieving root can read all sensitive files, modify system configurations, install persistent backdoors, and pivot to other systems on the network. The impact is confined to the vulnerable host (no lateral sub-system impact is scored), but root access effectively removes all OS-level security boundaries (SUSE Advisory).
A proof-of-concept reference has been noted in public sources, including a blog post describing the exploit mechanism (PoC Blog). The vulnerability is detected by both Nessus (plugin 281598) and Qualys (ID 6272502), indicating active scanner coverage. The EPSS score is approximately 0.016% (0.000160), reflecting a currently low probability of widespread exploitation. There is no evidence of in-the-wild exploitation by named threat actors, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report (Tenable Nessus, CIRCL).
smb4k_mounthelper) installed and accessible.smb4k_mounthelper (e.g., path traversal sequences or specially encoded filenames that redirect privileged file operations).smb4k_mounthelper with elevated (root) privileges and processes the attacker-controlled path values.smb4k_mounthelper running as root (e.g., /bin/bash, sh, python, perl, or network tools like curl/wget); smb4k_mounthelper invoked with unusual or malformed path arguments visible in process audit logs./var/log/audit/audit.log) entries showing smb4k_mounthelper accessing or writing to unexpected filesystem paths outside of standard mount points; KAuth/polkit logs showing elevated privilege grants to smb4k for unusual operations./etc/passwd, /etc/sudoers, /root/.ssh/authorized_keys, cron directories) with timestamps correlating to smb4k mount activity; unexpected SUID/SGID binaries created after a mount event.Users should upgrade smb4k to version 4.0.5 or later, which addresses this vulnerability. Debian has issued DSA-6092-1 covering smb4k, and Fedora has released updated packages; users on these distributions should apply the available security updates promptly. As a workaround where upgrading is not immediately possible, administrators should restrict which Samba shares users are permitted to mount via smb4k, avoid mounting shares from untrusted sources, and consider removing or restricting the smb4k_mounthelper KAuth helper permissions until patching is feasible (SUSE Advisory, Linux Security Debian).
SUSE's security team published a detailed advisory on December 10, 2025, describing the issues as "major" in the KAuth helper component, prompting downstream distributions including Debian and Fedora to issue security updates (SUSE Advisory). The vulnerability was discussed on the oss-security mailing list shortly after disclosure (oss-sec). Community discussion on Bluesky noted the local privilege escalation risk, though overall social media attention has been limited given the local-only attack vector and niche software affected.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."