CVE-2018-7445: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.
Other sources
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MikroTik RouterOSto a version that resolves this vulnerability.Fixed in 6.41.3/6.42rc27 - Compensating control
Restrict network access to the RouterOS SMB service so remote attackers cannot reach it before authentication (e.g., limit exposure at the network/firewall level).
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7445?
CVE-2018-7445 is rated as critical due to the potential for remote code execution.
How do I fix CVE-2018-7445?
To fix CVE-2018-7445, upgrade MikroTik RouterOS to version 6.41.4 or newer.
Who is affected by CVE-2018-7445?
CVE-2018-7445 affects MikroTik RouterOS versions up to and including 6.41.3.
What type of vulnerability is CVE-2018-7445?
CVE-2018-7445 is a buffer overflow vulnerability in the SMB service of MikroTik RouterOS.
Can attackers exploit CVE-2018-7445 without authentication?
Yes, attackers can exploit CVE-2018-7445 before authentication occurs, allowing for immediate code execution.