MikroTik RouterOS 7.24 及更早版本中的用户态 SMB 守护进程存在一个越界读取漏洞。未认证的 attackers 通过构造包含特定 字段值的极简 SMB1 SessionSetupAndX 帧,可以读取请求缓冲区末端之外的内存。该越界读取发生在 SessionSetupAndX 处理函数中,且在凭据验证之前,可能会暴露敏感的内存内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet