{
    "id": "CVE-2017-0160",
    "published": "2017-04-12 14:59:00",
    "last_modified": "2026-06-17 00:57:11",
    "cvss_score": "7.8",
    "cvss_severity": "HIGH",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "cwe": null,
    "description": "Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka \".NET Remote Code Execution Vulnerability.\"",
    "epss_score": "0.17848",
    "epss_percentile": "0.97085",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-30 18:17:16",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": ".net_framework"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "41903",
            "title": "Microsoft Windows - ManagementObject Arbitrary .NET Serialization Remote Code Execution",
            "date": "2017-04-20",
            "url": "https://www.exploit-db.com/exploits/41903"
        }
    ],
    "refs_list": [
        "http://www.securityfocus.com/bid/97447",
        "http://www.securitytracker.com/id/1038236",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160",
        "https://www.exploit-db.com/exploits/41903/",
        "http://www.securityfocus.com/bid/97447",
        "http://www.securitytracker.com/id/1038236",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160",
        "https://www.exploit-db.com/exploits/41903/"
    ]
}