CVE-2017-0160
HIGH.NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7 - Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0160. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a .NET deserialization vulnerability in Windows Management Instrumentation (WMI) DCOM clients, allowing arbitrary code execution on the calling machine when connecting to a malicious WMI server. The PoC replaces the WMI service with a fake server that returns a malicious serialized object, triggering RCE via BinaryFormatter deserialization.
Description
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
Exploits (1)
This exploit demonstrates a .NET deserialization vulnerability in Windows Management Instrumentation (WMI) DCOM clients, allowing arbitrary code execution on the calling machine when connecting to a malicious WMI server. The PoC replaces the WMI service with a fake server that returns a malicious serialized object, triggering RCE via BinaryFormatter deserialization.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H