CVE-2018-7445
MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
YesDecision
Descriptions
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.
Se ha encontrado un desbordamiento de búfer en el servicio MikroTik RouterOS SMB al procesar mensajes de petición de sesión NetBIOS. Los atacantes remotos con acceso al servicio pueden explotar esta vulnerabilidad y ejecutar código en el sistema. El desbordamiento ocurre antes de que tenga lugar la autenticación, por lo que es posible para un atacante remoto no autenticado explotarlo. Todas las arquitecturas y dispositivos que ejecutan RouterOS en versiones anteriores a la 6.41.3/6.42rc27 son vulnerables.
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-23 CVE Reserved
- 2018-03-15 CVE Published
- 2022-09-08 Exploited in Wild
- 2022-09-29 KEV Due Date
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-09-12 EPSS Updated
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103427 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44290 | 2024-08-05 | |
http://seclists.org/fulldisclosure/2018/Mar/38 | 2024-08-05 | |
https://www.coresecurity.com/advisories/mikrotik-routeros-smb-buffer-overflow | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | < 6.41.3 Search vendor "Mikrotik" for product "Routeros" and version " < 6.41.3" | - |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc11 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc12 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc14 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc15 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc18 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc2 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc20 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc23 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc24 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc27 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc5 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc6 |
Affected
| ||||||
Mikrotik Search vendor "Mikrotik" | Routeros Search vendor "Mikrotik" for product "Routeros" | 6.4.2 Search vendor "Mikrotik" for product "Routeros" and version "6.4.2" | rc9 |
Affected
|