Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
Loading...
Loading...
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.8 retained for reference. Confidence: HIGH.
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
September 13, 2017
April 22, 2026
Security Update Guide - Microsoft Security Response Center. Patch available via Microsoft Security Update
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8759MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (6 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Two versions of CVE-2017-8759 exploits
Open source ↗Simple C# implementation of CVE-2017-8759
Open source ↗Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft .NET Framework RCE. It could generate a malicious RTF file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
Open source ↗Microsoft Windows .NET Framework - Remote Code Execution
Open source ↗CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.
Open source ↗Running CVE-2017-8759 exploit sample.
Open source ↗NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2017-8759
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
msrc
CWE-20