CVE-2017-7285
HIGHMikroTik RouterOS 6.38.5 - Unauthenticated Denial of Service via TCP RST Packet Flood
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-7285. PoCs published by FarazPajohan.
AI-analyzed exploit summary This Perl script crafts and sends raw TCP packets with the RST flag set, targeting CVE-2017-7285, a vulnerability in Microsoft Office's graphics component. It continuously sends malformed packets to trigger a denial-of-service condition.
Description
A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.
Exploits (1)
This Perl script crafts and sends raw TCP packets with the RST flag set, targeting CVE-2017-7285, a vulnerability in Microsoft Office's graphics component. It continuously sends malformed packets to trigger a denial-of-service condition.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H