HIGH

CVE-2017-17762

CVSS v3

7.5

HIGH

EPSS Score

10.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.

Technical details

Published
8/29/2018

Frequently asked questions

What is CVE-2017-17762?

XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.

Is CVE-2017-17762 actively exploited?

Active exploitation of CVE-2017-17762 has not been confirmed. The EPSS score is 10.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2017-17762?

CVE-2017-17762 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2017-17762 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

Other 2017 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).