CVE-2018-7445
CRITICAL KEVMikroTik RouterOS < 6.41.3 - Unauthenticated Remote Code Execution via SMB NetBIOS Session Request
Title source: llmExploitation Summary
CVE-2018-7445 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added September 8, 2022. EIP tracks 2 public exploits from researchers including CoreLabs.
AI-analyzed exploit summary This exploit targets CVE-2018-7445, a buffer overflow in Samba, to achieve remote code execution. It uses a combination of ROP and shellcode to bypass protections and spawn a reverse shell.
Description
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.
Exploits (2)
This exploit targets CVE-2018-7445, a buffer overflow in Samba, to achieve remote code execution. It uses a combination of ROP and shellcode to bypass protections and spawn a reverse shell.
This repository contains functional exploit code for CVE-2018-7445, a buffer overflow vulnerability in MikroTik RouterOS SMB service. The exploit includes both MIPS and x86 payloads, demonstrating remote code execution by leveraging cache flushing techniques and ROP chains.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H