MikroTik RouterOS 在 7.24 之前的版本中存在一个堆内存损坏漏洞,该漏洞位于用户空间的 SMB 守护进程。该漏洞允许远程攻击者通过向 SMB1 SessionSetupAndX 处理器提供一个特制的 值,从而破坏相邻的堆内存。 具体机制如下:攻击者可以发送一个格式错误的 SMB1 请求,其中 字段会触发整数下溢(integer underflow)。下溢后的结果值随后被用作内存拷贝操作的拷贝长度,向一个更小的堆缓冲区进行数据拷贝,从而导致相邻堆内存被破坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet