CVE-2017-0160 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 17.8% (pctl 97)
Patch early
A public exploit exists.
Description
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 17.85% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-04-12 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | .net framework |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows - ManagementObject Arbitrary .NET Serialization Remote Code Execution | 2017-04-20 |
References
- http://www.securityfocus.com/bid/97447
- http://www.securitytracker.com/id/1038236
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160
- https://www.exploit-db.com/exploits/41903/
- http://www.securityfocus.com/bid/97447
- http://www.securitytracker.com/id/1038236
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160
- https://www.exploit-db.com/exploits/41903/
→ the Explorer · watch your stack · NVD