Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
BID:100742
Info
Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
| Bugtraq ID: | 100742 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-8759 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 14 2017 07:14PM |
| Credit: | Alex Berry and Dhanesh Kizhakkinan of FireEye, Inc. |
| Vulnerable: |
Microsoft .NET Framework 4.6.2 Microsoft .NET Framework 4.6.1 Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.7 Microsoft .NET Framework 4.6 Microsoft .NET Framework 4.5.2 Microsoft .NET Framework 3.5 Microsoft .NET Framework 2.0 SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
Microsoft Windows is prone to a remote code-execution vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Microsoft Windows is prone to a remote code-execution vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Exploit / POC
Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
Reports indicate that this issue is being exploited in the wild. Please see the references for more information.
Reports indicate that this issue is being exploited in the wild. Please see the references for more information.
Solution / Fix
Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Windows .NET Framework CVE-2017-8759 Remote Code Execution Vulnerability
References:
References:
- Exploit for CVE-2017-8759 detected and neutralized (Microsoft)
- FireEye Uncovers CVE-2017-8759: Zero-Day Used in the Wild to Distribute FINSPY (Fireeye)
- Microsoft Homepage (Microsoft)
- CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability (Microsoft)
- Vulnerability Note VU#101048 Microsoft .NET framework WSDL parser PrintClientPro (CERT)