CVE-2025-66003: Local users can perform a local root exploit via smb4k mounthelper
Published Dec 10, 2025
·Updated
An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ? before 4.0.5.
Affected Software
1 affected component
smb4k>4.0.5
Event History
Jan 8, 2026
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66003?
CVE-2025-66003 is a high-severity vulnerability that allows local users to exploit it for local root access.
2
How do I fix CVE-2025-66003?
To fix CVE-2025-66003, upgrade smb4k to version 4.0.5 or later.
3
Who is affected by CVE-2025-66003?
CVE-2025-66003 affects users of smb4k versions prior to 4.0.5.
4
What does CVE-2025-66003 involve?
CVE-2025-66003 involves an external control of file name or path vulnerability in smb4k that can be exploited through the smb4k mounthelper.
5
Can CVE-2025-66003 be exploited remotely?
No, CVE-2025-66003 requires local access to exploit the vulnerability.