CVE-2017-8759: Microsoft .NET Framework Remote Code Execution Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 88.7% chance of exploitation in the next 30 days.

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

Affected products

  • Microsoft .NET Framework: version 4.5.2 only; version 3.5.1 only; version 3.5 only; version 2.0 only; version 4.6.1 only; version 4.6 only; …

Published 2017-09-13. Last modified 2026-06-17.