CVE detail
CVE-2017-8759
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
28 source links · newest first
The typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.
vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PMSeveral Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.
newswww.securityweek.comMay 13, 2020, 4:43 PM- Have you patched these top 10 routinely exploited vulnerabilities?Help Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →
newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM A threat actor active since at least 2017 has been mainly targeting victims with information stealers and remote access Trojans (RATs), Cisco’s Talos security researchers explain.
newswww.securityweek.comJul 17, 2019, 6:11 AMA cyber-espionage group, tracked as APT40, apparently linked to the Chinese government is focused on targeting countries important to the country’s Belt and Road Initiative. The cyber-espionage group tracked as APT40 (aka TEMP.Periscope, TEMP.Jumper, and Leviathan), apparently linked to the Chinese government, is focused on targeting countries important to the country’s Belt and Road Initiative […]
newssecurityaffairs.comMar 6, 2019, 7:59 AMAPT40 Hackers Appear to be Supporting China’s Belt and Road Initiative
newswww.securityweek.comMar 5, 2019, 1:19 PM- Backdoor Targets U.S. Companies via LinkedInSecurityWeek
A malicious campaign attempting to infect business users in the United States with a backdoor has been ongoing for over half a year, Proofpoint reports.
newswww.securityweek.comFeb 26, 2019, 11:17 AM A recently discovered Microsoft Office document exploit builder kit dubbed ThreadKit has been used to spread a variety of malware, including RATs and banking Trojans. Security experts at Proofpoint recently discovered a Microsoft Office document exploit builder kit dubbed ThreadKit that has been used to spread a variety of malware, including banking Trojans and RATs (i.e. Trickbot, Chthonic, FormBook and […]
newssecurityaffairs.comMar 28, 2018, 12:37 PMMicrosoft Dissects FinFisher’s Complex Infection Process
newswww.securityweek.comMar 4, 2018, 5:54 PM- Threat actors are delivering the Zyklon Malware exploiting three Office vulnerabilitiesSecurity Affairs
Security experts from FireEye have spotted a new strain of the Zyklon malware that has been delivered by using new vulnerabilities in Microsoft Office. Researchers at FireEye reported the malware was used in attacks against organizations in the telecommunications, financial, and insurance sectors. Zyklon has been spotted for the first time in 2016, it is a publicly available […]
newssecurityaffairs.comJan 18, 2018, 9:19 AM - Zyklon Malware Delivered via Recent Office FlawsSecurityWeek
A piece of malware known as Zyklon has been delivered by cybercriminals using some relatively new vulnerabilities in Microsoft Office, FireEye reported on Wednesday.
newswww.securityweek.comJan 17, 2018, 7:32 PM - Threat Actors Quickly Adopt Effective ExploitsSecurityWeek
Cybercriminals and nation state groups were quick to adopt the most effective exploits last year, a new AlienVault report reveals.
newswww.securityweek.comJan 17, 2018, 3:34 PM The notorious Cobalt hacking group has started to exploit a 17-year-old vulnerability in Microsoft Office that was addressed earlier this month, security researchers claim.
newswww.securityweek.comNov 27, 2017, 6:40 PM- The Cobalt group is exploiting the CVE-2017-11882 Microsoft Office flaw in targeted attacksSecurity Affairs
A few days after details about the CVE-2017-11882 Microsoft Office flaw were publicly disclosed, the firm Reversing Lab observed Cobalt group using it. A few days after details about the CVE-2017-11882 Microsoft Office vulnerability were publicly disclosed, security experts from firm Reversing Lab observed criminal gang using it in the wild. The gang is the notorious Cobalt hacking group […]
newssecurityaffairs.comNov 26, 2017, 2:06 PM What could do more damage to your business: CVE-2017-8759 or Epic Banana? CVE-2017-0262 or Extra Bacon? Funny exploit names are all the rage: This year we’ve had WannaCry (powered by EternalBlue), NotPetya, Krack, and Pork Explosion. In years gone by we’ve had Heartbleed, StageFright, Shellshock, Dirty Cow, Poodle, and Freak. Many come with a nice […]
newswww.csoonline.comNov 23, 2017, 1:30 AM- Cobalt Hackers Now Targeting Banks DirectlySecurityWeek
The notorious Cobalt hackers have shown a change in tactics recently, switching their attacks to targeting banks themselves, instead of bank customers, Trend Micro reports.
newswww.securityweek.comNov 21, 2017, 5:04 PM Courtesy of the Windows Defender Exploit Guard that ships with Windows 10 Fall Creators Update, systems running Microsoft’s Windows 10 operating system can fend off emerging threats, Microsoft says.
newswww.securityweek.comNov 1, 2017, 5:24 PMSecurity researchers at Proofpoint spotted a cyber espionage campaign conducted by a group previously linked to China. The hackers have been using a recently patched .NET vulnerability, tracked as CVE-2017-8759, in attacks aimed at organizations in the United States. “Proofpoint researchers are tracking an espionage actor targeting organizations and high-value targets in defense and government. […]
newssecurityaffairs.comOct 19, 2017, 7:53 AMA cyber espionage group previously linked to China has been using a recently patched .NET vulnerability in attacks aimed at organizations in the United States, including a shipbuilding company and a university research center with ties to the military.
newswww.securityweek.comOct 18, 2017, 2:16 PMAdobe has released an out-of-band security update for Adobe Flash Player that patches a zero-day remote code execution vulnerability actively exploited in the wild. Kaspersky Lab researchers spotted the live attacks on October 10, 2017, and say that the exploit is delivered through a Microsoft Word document and deploys the most recent version of the FinSpy (aka FinFisher) commercial malware developed by Gamma International. The attack leveraging CVE-2017-11292 The researchers believe that the zero-day is … More →
newswww.helpnetsecurity.comOct 17, 2017, 4:40 PMSecurity researchers from Kaspersky Labs spotted the BlackOasis APT group exploiting a new zero-day RCE vulnerability in Adobe Flash. Security researchers from Kaspersky Labs have discovered a new zero-day remote code execution vulnerability in Adobe Flash, tracked as CVE-2017-11292, which was being actively exploited by hackers in the wild to deliver the surveillance software FinSpy. Hackers belonging to the […]
newssecurityaffairs.comOct 17, 2017, 7:05 AM- Decoy Microsoft Word document delivers malware through a RATMalwarebytes Labs
In this post, we take a look at a Microsoft Word document which itself is somewhat clean, but is used to…
newswww.malwarebytes.comOct 12, 2017, 5:00 PM New campaigns featuring the infamous FinFisher spyware are using a previously unseen infection vector, strongly suggesting that Internet service providers (ISPs) might be involved in the distribution process, ESET security researchers warn.
newswww.securityweek.comSep 21, 2017, 5:09 PM- Patch Tuesday: 80+ vulnerabilities fixed, one exploited in the wildHelp Net Security
As part of its regular, monthly Patch Tuesday update, Microsoft has released patches for 81 new vulnerabilities, including a zero-day in the .NET Framework. The September patch dump also includes details of a spoofing vulnerability in the Windows Bluetooth driver (CVE-2017-8628), which has been disclosed as part of the BlueBorne batch of vulnerabilities. The flaw was apparently patched silently in July, but Microsoft chose to delay releasing details about it until other vendors could develop … More →
newswww.helpnetsecurity.comSep 13, 2017, 6:53 PM Microsoft has just released the September Patch Tuesday, a huge batch of security updates to address 81 vulnerabilities including Blueborne issue. Microsoft has just released the September Patch Tuesday, a huge batch of security updates to address 81 vulnerabilities in almost any supported versions of Windows and other MS products. The batch includes security update to addresses […]
newssecurityaffairs.comSep 13, 2017, 5:25 PM- Microsoft Patches Zero-Day, Many Other FlawsSecurityWeek
Microsoft’s Patch Tuesday updates for September 2017 address roughly 80 vulnerabilities, including a zero-day exploited by threat actors to deliver spyware and several flaws that have been publicly disclosed.
newswww.securityweek.comSep 13, 2017, 8:38 AM One of the vulnerabilities patched by Microsoft with this month’s security updates is a zero-day flaw exploited by threat actors to deliver FinFisher malware to Russian-speaking individuals.
newswww.securityweek.comSep 12, 2017, 6:34 PM- PSA: New Microsoft Word 0day used in the wildMalwarebytes Labs
Microsoft has just patched an important vulnerability in Microsoft Word during its latest patch Tuesday cycle. According to the security firm…
newswww.malwarebytes.comSep 12, 2017, 5:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2017-8543CVSS 9.8 · Critical
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1,…
- CVE-2017-8540CVSS 7.8 · High
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows…
- CVE-2017-0263CVSS 7.8 · High
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607,…
- CVE-2017-0222CVSS 8.8 · High
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is…
- CVE-2017-0213CVSS 7.3 · High
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511…
KEV listed5 mentions - CVE-2017-0210CVSS 8.8 · High
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one…
KEV listed4 mentions