PT-2026-93728 · Mikrotik · Routeros
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MikroTik RouterOS versions prior to 7.24
Description
A heap memory corruption issue exists in the userspace SMB daemon. A remote attacker can corrupt adjacent heap memory by sending a malformed SMB1 request to the SMB1 SessionSetupAndX handler. By supplying a crafted
uniPwdLen value, an integer underflow is triggered, which causes the resulting value to be used as the copy length during a memory copy operation into a smaller heap buffer.Recommendations
Update MikroTik RouterOS to version 7.24 or later.
Fix
Integer Underflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Routeros