CVE-2021-44141
published 2022-02-21CVE-2021-44141: All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.09%
61.9th percentile
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.16.0+dfsg-2 (bookworm) | samba 2:4.16.0+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| redhat | storage | — | — |
| samba | samba | < 4.15.5 | 4.15.5 |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the
vendor_msrc·2022-02-08·CVSS 4.3
CVE-2021-44141 [MEDIUM] CWE-59 All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this
Red Hat
samba: Information leak via symlinks of existance of files or directories outside of the exported share
vendor_redhat·2022-01-31·CVSS 4.3
CVE-2021-44141 [MEDIUM] CWE-59 samba: Information leak via symlinks of existance of files or directories outside of the exported share
samba: Information leak via symlinks of existance of files or directories outside of the exported share
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.
A vulnerability was found in Samba due to an insecure link following. By querying a symlink inside the exported share using SMB1 with unix extensions turned on, an attacker can discover if a named or directory exists on the filesystem outside the exported share. This flaw allows a remote authenticated attacker to obtain sensitive information.
Mitigation: Do not enable SMB1 (please note SMB1
Debian
CVE-2021-44141: samba - All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using...
vendor_debian·2021·CVSS 4.3
CVE-2021-44141 [MEDIUM] CVE-2021-44141: samba - All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using...
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.
Scope: local
bookworm: resolved (fixed in 2:4.16.0+dfsg-2)
bullseye: open
forky: resolved (fixed in 2:4.16.0+dfsg-2)
sid: resolved (fixed in 2:4.16.0+dfsg-2)
trixie: resolved (fixed in 2:4.16.0+dfsg-2)
GHSA
GHSA-fmfh-pcgm-2499: All versions of Samba prior to 4
ghsa_unreviewed·2022-02-22
CVE-2021-44141 [MEDIUM] CWE-200 GHSA-fmfh-pcgm-2499: All versions of Samba prior to 4
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.
OSV
CVE-2021-44141: All versions of Samba prior to 4
osv·2022-02-21·CVSS 4.3
CVE-2021-44141 [MEDIUM] CVE-2021-44141: All versions of Samba prior to 4
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-21
Published