EXPOSURES › CVE-2017-8759
CVE-2017-8759
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft .NET Framework RCE vulnerability (CVE-2017-8759) was actively exploited in the wild, allowing attackers to take full control of systems.
This unpatched RCE flaw in the .NET Framework allowed remote attackers to execute arbitrary code on affected systems, leading to potential data breaches and ransomware deployment. DIB organizations must ensure all .NET Framework components are patched and monitored for exploitation attempts, as this vulnerability was actively exploited in the wild before widespread patching.
Shame score — A known RCE vulnerability in a widely deployed framework was actively exploited in the wild, indicating a failure to patch known CVEs and leaving systems vulnerable to remote compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.
"Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system."
"GitHub - nccgroup/CVE-2017-8759: NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements"
"CVE-2017-8759 - Microsoft .NET Framework Remote Code Execution Vulnerability - [Actively Exploited]"
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |