SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-7445

MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

KEVCRITICAL 9.8EPSS 60.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
60.81% probability · 99th percentile
CISA KEV
Listed 8 September 2022 · due 29 September 2022
Weakness
CWE-119
Affected
mikrotik/routeros
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://www.coresecurity.com/core-labs/advisories/mikrotik-routeros-smb-buffer-overflow#vendor_update, https://mikrotik.com/download; https://nvd.nist.gov/vuln/detail/CVE-2018-7445

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.