SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Badlock : A Critical Samba Vulnerability

Badlock : A Critical Samba Vulnerability

A critical vulnerability found in Samba which affects all Windows platforms, termed as badlock. It will be patched on April 12, 2016. This is called samba badlock vulnerability. A vulnerability management tool can mitigate this vulnerability.

Mar 23, 2016By Kumarswamy S2 min read

A critical vulnerability found in Samba which affects all Windows platforms, termed as badlock. It will be patched on April 12, 2016. This is called samba badlock vulnerability. A vulnerability management tool can mitigate this vulnerability.

credit : badlock.org
credit : badlock.org

Samba is an open source implementation of the SMB/CIFS network protocol, which runs on non-windows operating systems like Unix, IBM System 390, Linux, OpenVMS and other operating systems and allows them to interact with Microsoft Windows to access files and printer over a network. Also, a auto patching solution can patch this vulnerability.

Samba Badlock vulnerability discovered by Stefan Metzmacher, a member of the international Samba Core Team and works at SerNet on Samba. However, he reported the bug to Microsoft and has been working with them to bring out the patch to badlock flaw.

From badlock.org:

plaintext
On April 12th, 2016 a crucial security bug in Windows and Samba will be disclosed. We call it: Badlock.

Engineers at Microsoft and the Samba Team are working together to  get this problem fixed. Patches will be released on April 12th.

Admins and everyone responsible for Windows or Samba server infrastructure: Mark the date. (Again: It's April 12th, 2016.)

Please get yourself ready to patch all systems on this day. We are pretty sure that there will be exploits soon after we publish all relevant information.

However some of the deleted tweets from the person registered badlock.org domain, Johannes Loxen reveal two things :

  • The reason behind disclosing the vulnerability is “SerNet gets marketing” as a side effect.
badlock_marketing
badlock_marketing
  • Another tweet is giving us clue on the impact of exploitation, which is “admin accounts for everyone on the same LAN”.

More information about this vulnerability going disclosed on Microsoft Patch Tuesday (i.e. 12th, April, 2016) by Samba Team and Microsoft.

SecPod Saner

A free vulnerability mitigation software. Build strong defense.

Kumarswamy S

badlock_admin_lan
badlock_admin_lan

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026