CVE-2025-66002: Local users can perform arbitrary unmounts via smb4k mount helper due to lack of input validation
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66002?
CVE-2025-66002 is rated as high severity due to its ability to allow arbitrary unmount operations by local users.
How do I fix CVE-2025-66002?
To fix CVE-2025-66002, update to the latest version of smb4k that addresses this vulnerability.
Who is affected by CVE-2025-66002?
Local users of smb4k are affected by CVE-2025-66002, which allows potential command execution through argument injection.
What kind of vulnerability is CVE-2025-66002?
CVE-2025-66002 is an Improper Neutralization of Argument Delimiters in a Command vulnerability, commonly referred to as argument injection.
Is there a workaround for CVE-2025-66002?
As of now, the recommended action is to update smb4k, as specific workarounds may not be effective against this vulnerability.