Attacks likely against unpatched Mac OS Samba bug

Two months after Samba fixed the software, Mac users are still waiting for Apple update

Symantec last week warned Mac OS X users that the addition of an exploit to the Metasploit hacking framework had boosted the threat posed by an unpatched bug in Samba, the open-source file- and print-sharing software included with the Apple operating system.

Although the vulnerability was disclosed May 14 and patched that same day by the Samba community, Apple has not updated Mac OS X with a fix, said Symantec's Alfred Huger, vice president of engineering with the security company's response group.

"This is significant exposure for Mac OS X users," said Huger. "Samba is used in virtually every mixed environment where there are Macs and PCs, and the threat profile is much higher now that an exploit has been added to Metasploit."

Samba, which is also used by most Linux distributions to file- and print-sharing with Windows systems, is turned on in Mac OS X when users activate the Windows Sharing feature.

This month, a trio of Brazilian researchers who collaborate as Rise Security released Mac OS X attack code for the Samba vulnerability. According to Symantec, the Rise code is "almost identical" to what the company's security team discovered in late May.

More important, said Huger, is that Rise also contributed their code to Metasploit, an open-source platform for creating, testing and launching exploit code. "Once we see something in Metasploit, we know it's likely we'll see it used in attacks," he said as he explained why Symantec had amped its earlier warning. "Every Unix-based break-in that's not hand-crafted, in other words not with the attacker sitting at the keyboard during the attack, is made with a couple of different tools, and Metasploit is by far the most popular."

The Rise-developed, Metasploit-distributed exploit successfully attacks a fully-patched Mac OS X 10.4.10 system, added Symantec, and results in the attacker gaining root privileges on the Mac.

"There is a very high probability that attackers will attempt to leverage [the exploit] to compromise Apple users, especially those connected to wireless networks," said Symantec in a separate alert issued Wednesday to customers of its DeepSight Threat network. "Wireless networks are an especially high threat, because users' systems may be exposing the service that may otherwise be protected by a gateway firewall installed on a home network."

Symantec recommended that users disable the Windows Sharing service until Apple produces a patch. Technically-astute users, however, may be able to handle the more rigorous chore of compiling the latest version of Samba manually in lieu of waiting for Apple.

Apple, which has not updated Samba within Mac OS X since March 2005, did not respond to e-mail asking for comment.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Gregg Keizer

Gregg Keizer

Show Comments

Brand Post

Bitdefender 2019

Taking cybersecurity to the highest level and order now for a special discount on the world’s most awarded and trusted cybersecurity. Be aware without a care!

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?