Executive brief
A stack-based buffer overflow vulnerability exists in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Unauthenticated remote attackers can exploit this to execute arbitrary code on the device.
Affected products
- MikroTik RouterOS before 6.41.3, before 6.42rc27
Timeline
- 2018-03-12: disclosed: Full Disclosure mailing list post
- 2018-04-24: other: Initial NIST analysis
- 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-29: other: CISA required action due date