CVE-2017-8759: Microsoft .NET Framework Remote Code Execution Vulnerability
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
Other sources
Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8759?
CVE-2017-8759 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2017-8759?
To fix CVE-2017-8759, you should apply the relevant Microsoft security updates for the .NET Framework versions that are affected.
What versions of .NET Framework are impacted by CVE-2017-8759?
CVE-2017-8759 affects .NET Framework versions 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, and 4.7.
Can I test for CVE-2017-8759 in my environment?
You can test for CVE-2017-8759 by validating if the vulnerable .NET Framework versions are present and checking for applied patches.
What kind of attack vector does CVE-2017-8759 utilize?
CVE-2017-8759 can be exploited through malicious documents or applications that lead to remote code execution.