CVE-2017-13779: Gstn India Goods And Services Tax Network Offline Utility Tool

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example, a local user could create VBScript code for a TCP reverse shell, and use that later for Remote Command Execution.

Affected products

  • Gstn India Goods And Services Tax Network Offline Utility Tool: up to and including 1.1

Published 2017-09-14. Last modified 2026-06-17.