CVE-2017-8759

ENISA EUVD: EUVD-2017-17705 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 5, 2026 4 articles Published: 2017-09-13

EPSS Score

Source: FIRST.org · 2026-05-23
93.97%
probability
This CVE has a 93.97% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.8
HIGH
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 (legacy)

9.3
HIGH
Access Vector
Network
Access Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

VulnerabilityLookup (CNA)
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

Affected Products

Microsoft Corporation
Microsoft .NET Framework
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7

Attack Intelligence

Google Project Zero

Patched
Sept. 12, 2017
Reported by
Genwei Jiang and Dhanesh Kizhakkinan of FireEye, Inc.
Root Cause Analysis
???

Exploits & PoC

bhdresh/CVE-2017-8759

Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Mic

312 2018-09-10
Voulnet/CVE-2017-8759-Exploit-sample

Running CVE-2017-8759 exploit sample.

255 2020-01-23
vysecurity/CVE-2017-8759

CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.

176 2017-09-14
nccgroup/CVE-2017-8759

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

94 2017-09-19
JonasUliana/CVE-2017-8759

Simple C# implementation of CVE-2017-8759

5 2017-09-17
ashr/CVE-2017-8759-exploits

Two versions of CVE-2017-8759 exploits

2 2017-09-19
BasuCert/CVE-2017-8759

CVE-2017-8759 Research

1 2017-09-15
homjxi0e/CVE-2017-8759_-SOAP_WSDL

CVE-2017-8759 Remote Code Execution Vulnerability On SOAP WDSL - Microsoft .NET Framework 4.6.2 Microsoft .NET Framework 4.6.1 Microsoft .NET Framew

0 2017-09-21
0 2017-09-17
ChaitanyaHaritash/CVE-2017-8759

Just My ports of CVE-2017-8759

0 2018-12-11
0 2019-05-30
adeljck/CVE-2017-8759

CVE-2017-8759 微软word漏洞利用脚本

0 2019-06-25
zhengkook/CVE-2017-8759

CVE-2017-8759 use file

0 2020-01-02
varunsaru/SNP

CVE-2017-8759 || report related with execute code vulnerability

0 2020-05-12
GayashanM/OHTS

CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability

0 2020-05-13
17 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 93.97%
CVSS v3.1 7.8
Mentions 4
Last Seen Oct 16, 2017

CNA Information

CNA Assigner
microsoft

Analyst Note

Auto-imported from Google Project Zero — confirmed zero-day by definition.

Threat Actors 4

Stone Panda
apt_group Information theft and espionage 🇨🇳 CN
DNSpionage
apt_group Information theft and espionage 🇮🇷 IR
Kinsing
apt_group 🇷🇺 RU
TeamTNT
apt_group 🇩🇪 DE

Triage Info

Decided atMar 05, 2026
Published DateSep 13, 2017