cbcvebase.
CVE-2017-8759
published 2017-09-13

CVE-2017-8759: Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application…

PriorityP185high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
88.70%
99.8th percentile
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoft_corporationmicrosoft_net_framework
msrcmicrosoft_net_framework_2.0_service_pack_2
msrcmicrosoft_net_framework_3.5
msrcmicrosoft_net_framework_3.5.1
msrcmicrosoft_net_framework_4.5.2
msrcmicrosoft_net_framework_4.6
msrcmicrosoft_net_framework_4.6.1
msrcmicrosoft_net_framework_4.6.2_4.7
msrcmicrosoft_net_framework_4.6_4.6.1_4.6.2_4.7
msrcmicrosoft_net_framework_4.7

Detection & IOCsextracted from sources · hover to see the quote

hashccb1fa5cdbc402b912b01a1838c1f13e95e9392b3ab6cc5f28277c012b0759f9
hashdcad7f5135ffa5e98067b46feec2563be8c67934eb3b14ef1aad8ff7fe0892c5
hashdab05e284a9cbc89d263798bae40c9633ff501e19568c2ca21ada58e90d66891
hash2b4760b5bbe982a7e26af4ee618f8f2dcc67dfe0211f852bf549db457acd262c
hashe9ab3195f3a974861aa1135862f6c24df1d7f5820e8c2ac6e61a1a5096457fc3
hash0dedb345d90dbba7e83b2d618c93d701ed9e9037aa3b7c7c58b62e53dab7d2ce
hasheb4325ef1cbfba85b35eec3204e7f79
ip5.135.237.216
ip86.106.131.207
urlhttps://5.135.237.216/RLxF
urlhttp://visa-fraud-monitoring.com/t.dll
urlhttp://servicecentrum.info/test.xml
domainvisa-fraud-monitoring.com
domainservicecentrum.info
port443
port443
filenamessssss.ddd
filenameevent.dll
commandodbcconf.exe /S /A {REGSVR ""C:\Users\Public\file.dll""}
otherMS.DotNET.Framework.SOAP.Remote.Code.Execution
  • CVE-2017-8759 exploitation involves embedding a SOAP moniker in an RTF file that retrieves a malicious SOAP WSDL definition (XML file) from a remote server; the XML content is parsed and compiled by .NET Framework, which Microsoft Office then loads as a library.
  • ANEL malware (delivered via CVE-2017-8759) uses DLL side-loading: legitimate accevent.exe loads a malicious event.dll from the same directory, which then decrypts and loads ssssss.ddd (lena_http.bin). Monitor for accevent.exe loading non-standard DLLs.
  • ANEL C2 communications use blowfish, XOR, and Base64 encryption; network traffic analysis should look for Base64-encoded blobs in HTTP POST requests to C2 servers associated with ANEL.
  • Cobalt Group's macro-based infection chain uses odbcconf.exe to execute a dropped DLL and regsvr32.exe to execute SCT/JScript files; monitor for these LOLBin invocations with unusual arguments.
  • Fortinet IPS signature 'MS.DotNET.Framework.SOAP.Remote.Code.Execution' directly covers CVE-2017-8759 exploitation attempts.
  • ·The MD5 hash for the CVE-2017-8759 RTF attachment (eb4325ef1cbfba85b35eec3204e7f79) appears truncated (31 hex chars instead of 32); verify against authoritative sources before using for detection.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.