Improper input validation in Microsoft .NET Framework - CVE-2017-8759
Published: September 12, 2017 / Updated: November 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to uncpecified error when processing untrusted input. A remote unauthenticated attacker can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note: this vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2017-8759
Links to Public Exploits and PoC-codes
- Exploit #2135 - CVE-2017-8759-Exploit-sample2 () (March 18, 2020)
- Exploit #153 - CVE-2017-8759 (Simple C# implementation of CVE-2017-8759) (March 18, 2020)
- Exploit #154 - CVE-2017-8759-exploits (Two versions of CVE-2017-8759 exploits) (March 18, 2020)
- Exploit #155 - CVE-2017-8759 (NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements) (March 18, 2020)
- Exploit #156 - CVE-2017-8759 (Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft .NET Framework RCE. It could generate a malicious RTF file and deliver metasploit / (March 18, 2020)
- Exploit #157 - CVE-2017-8759-Exploit-sample (Running CVE-2017-8759 exploit sample.) (March 18, 2020)
- Exploit #158 - CVE_Assessments_01_2020 () (March 18, 2020)
- Exploit #1308 - Microsoft Windows .NET Framework - Remote Code Execution (March 18, 2020)