AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-7560

MEDIUM · CVSS 6.5 EPSS 12.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-03-13 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2015-7560
Severity
MEDIUM
CVSS
6.5
EPSS
12.94%

Original Filing — NVD Description

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.