{"id":"CVE-2025-66003","title":"An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ? before …","summary":"An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ? before …","severity":"none","cwe":["CWE-73"],"published":"2026-01-08","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66003","references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-66003","label":"meissner@suse.de"},{"url":"https://security.opensuse.org/2025/12/10/smb4k-major-issues-in-kauth-helper.html","label":"meissner@suse.de"}],"tags":["nvd"],"epss":0.00119,"epssPercentile":0.01579,"ingestedAt":"2026-09-30T22:27:27.738Z","slug":"CVE-2025-66003","body":"## Overview\n\nAn External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ? before 4.0.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}