CVE-2018-7445
CRITICAL KEVMikrotik Routeros < 6.41.3 - Memory Corruption
Title source: ruleDescription
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.
Exploits (2)
References (5)
Scores
CVSS v3
9.8
EPSS
0.8756
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-09-08
VulnCheck KEV
2020-12-01
InTheWild.io
2018-05-12
ENISA EUVD
EUVD-2018-19176
CWE
CWE-119
Status
published
Products (2)
mikrotik/routeros
6.42 rc11 (12 CPE variants)
mikrotik/routeros
< 6.41.3
Published
Mar 19, 2018
KEV Added
Sep 08, 2022
Tracked Since
Feb 18, 2026