Skip to content
COOEY

EXPOSURES › CVE-2018-7445

CVE-2018-7445

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-7445 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

MikroTik RouterOS CVE-2018-7445 exploited for code execution

An unpatched stack-based buffer overflow in MikroTik RouterOS allowed remote attackers to execute arbitrary code via a NetBIOS session request message, posing a high severity security risk to DIB networks.

Shame score — Active exploitation of a known vulnerability with no indication of patching, leading to potential unauthorized system access and code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.