CVE-2017-9822

HIGH KEV RANSOMWARE NUCLEI

DotNetNuke < 9.1.1 - Remote Code Execution via Cookie Deserialization

Title source: manual
STIX 2.1

Exploitation Summary

CVE-2017-9822 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns. EIP tracks 5 public exploits from researchers including murataydemir, Tnot123, tranphuc2005, including a Metasploit module exploits/windows/http/dnn_cookie_deserialization_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository provides a detailed proof-of-concept for CVE-2017-9822, a deserialization vulnerability in DotNetNuke (DNN) versions 5.0.0 to 9.3.0. It includes payloads for both detection (safe mode) and exploitation (aggressive mode) using YSoSerial.net to achieve remote code execution via malicious cookie manipulation.

Description

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

Exploits (5)

nomisec WORKING POC 20 stars
by murataydemir · remote
https://github.com/murataydemir/CVE-2017-9822

This repository provides a detailed proof-of-concept for CVE-2017-9822, a deserialization vulnerability in DotNetNuke (DNN) versions 5.0.0 to 9.3.0. It includes payloads for both detection (safe mode) and exploitation (aggressive mode) using YSoSerial.net to achieve remote code execution via malicious cookie manipulation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: DotNetNuke (DNN) versions 5.0.0 - 9.3.0
No auth needed
Prerequisites: DotNetNuke instance with default 404 error page handling · Ability to send crafted HTTP requests to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by Tnot123 · remote
https://github.com/Tnot123/cve-2017-9822

This repository provides a detailed writeup and analysis of CVE-2017-9822, a critical RCE vulnerability in DotNetNuke (DNN) versions prior to 9.1.1. The vulnerability involves insecure deserialization of the DNNPersonalization cookie, leading to remote code execution.

Classification
Writeup 100%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: DotNetNuke (DNN) < 9.1.1
No auth needed
Prerequisites: Access to a vulnerable DNN instance · Ability to send crafted HTTP requests with a malicious DNNPersonalization cookie
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by tranphuc2005 · remote-auth
https://github.com/tranphuc2005/CVE-2017-9822

This repository provides a detailed analysis of CVE-2017-9822, an XXE/Insecure Deserialization vulnerability in DotNetNuke (DNN) leading to RCE via cookie manipulation. It includes debugging steps and payload creation but lacks a full exploit PoC.

Classification
Writeup 90%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Theoretical
Target: DotNetNuke (DNN Platform) < 9.1.1
No auth needed
Prerequisites: Access to a vulnerable DNN instance · Ability to send crafted HTTP requests with malicious cookies
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Jon Park, Jon Seigel · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/dnn_cookie_deserialization_rce.rb

This Metasploit module exploits a deserialization vulnerability in DotNetNuke (DNN) versions 5.0.0 to 9.3.0-RC. It leverages the DNNPersonalization cookie to execute arbitrary code by manipulating XML-based profile data during deserialization.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: DotNetNuke (DNN) versions 5.0.0 to 9.3.0-RC
No auth needed
Prerequisites: Target must be running a vulnerable version of DNN · DNN must be configured to handle 404 errors with its built-in error page
devstral-2 · analyzed Apr 24, 2026 Full analysis →
exploitdb WORKING POC
rubyremotewindows
https://www.exploit-db.com/exploits/48336

This Metasploit module exploits a deserialization vulnerability in DotNetNuke (DNN) versions 5.0.0 to 9.3.0-RC by crafting a malicious DNNPersonalization cookie, leading to remote code execution. The exploit leverages the ObjectStateFormatter deserialization gadget chain to execute arbitrary commands.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: DotNetNuke (DNN) 5.0.0 to 9.3.0-RC
No auth needed
Prerequisites: Target must be running a vulnerable version of DNN · DNN must be configured to handle 404 errors with its built-in error page (default configuration)
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Execution
HIGHby milo2012
FOFA: app="dotnetnuke"

References (4)

Core 4
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102213
Product, Vendor Advisory x_refsource_confirm
http://www.dnnsoftware.com/community/security/security-center

Scores

CVSS v3 8.8
EPSS 0.9429
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-01-21
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2018-0710
Ransomware Use Confirmed
CWE
CWE-94
Status published
Products (3)
dnnsoftware/dotnetnuke < 9.1.1
DotNetNuke/DotNetNuke CMS Fixed in 9.1.1 DotNetNuke CMS Fixed in 9.1.1
nuget/DotNetNuke.Core 0 - 9.1.1NuGet
Published Jul 20, 2017
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026