Samba 4.6.3 with a writable guest share, vulnerable to SambaCry (CVE-2017-7494): a client that uploads a shared library to the share can make smbd load it by naming its server-side path as a named pipe.
Not startedDockercommit 4803e9dx86_64 · aarch64Secret
Exploit CVE-2017-7494 (SambaCry) to get a shell on the Samba server.
The brief for this lab lives in its repository.