---
id: CVE-2025-66003
title: >-
  An External Control of File Name or Path vulnerability in smb4k allowsl ocal
  users to perform a local root exploit via smb4k mounthelper if they can access
  and control the contents of a Samba shareThis issue affects smb4k: from ?
  before …
summary: >-
  An External Control of File Name or Path vulnerability in smb4k allowsl ocal
  users to perform a local root exploit via smb4k mounthelper if they can access
  and control the contents of a Samba shareThis issue affects smb4k: from ?
  before …
severity: none
cwe:
  - CWE-73
published: '2026-01-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66003'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-66003'
    label: meissner@suse.de
  - url: >-
      https://security.opensuse.org/2025/12/10/smb4k-major-issues-in-kauth-helper.html
    label: meissner@suse.de
tags:
  - nvd
epss: 0.00119
epssPercentile: 0.01572
ingestedAt: '2026-09-30T22:27:27.738Z'
---

## Overview

An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ? before 4.0.5.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
