Umbra Wiki cve cve/CVE-2018-7445
Back to wiki

CVE-2018-7445 — MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

provenance: imported · CVE: CVE-2018-7445

CVE-2018-7445: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project MikroTik
Product RouterOS
Date added 2022-09-08
Due date 2022-09-29
Ransomware campaign use Unknown

Description

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.coresecurity.com/core-labs/advisories/mikrotik-routeros-smb-buffer-overflow#vendor_update, https://mikrotik.com/download; https://nvd.nist.gov/vuln/detail/CVE-2018-7445

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-7445
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog