CVE-2017-0160
high · 7.8Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
7.8
CVSS
17.8%
EPSS (exploit prob.)
97th
EPSS percentile
2017-04-12
Published
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | .net_framework | 2.0 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 3.5.1 |
| microsoft | .net_framework | 4.5.2 |
| microsoft | .net_framework | 4.6 |
| microsoft | .net_framework | 4.6.1 |
| microsoft | .net_framework | 4.6.2 |
| microsoft | .net_framework | 4.7 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/97447
- http://www.securitytracker.com/id/1038236
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160
- https://www.exploit-db.com/exploits/41903/
- http://www.securityfocus.com/bid/97447
- http://www.securitytracker.com/id/1038236
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160
- https://www.exploit-db.com/exploits/41903/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-0160