KEV 2017

86 CISA Known Exploited Vulnerabilities from 2017

Critical 23

March 2026

October 2025

February 2025

August 2023

March 2023

January 2023

August 2022

June 2022

May 2022

April 2022

March 2022

February 2022

January 2022

December 2021

November 2021

High 57

March 2025

September 2024

June 2024

September 2023

April 2023

September 2022

June 2022

May 2022

April 2022

March 2022

CVE-2017-0146

Microsoft Windows SMBv1 — EternalSynergy: NSA Equation Group SMBv1 RCE; Shadow Brokers Leak; WannaCry/NotPetya Propagation; Patched MS17-010 (March 2017)

CVSS 8.8
CVE-2017-6334

NETGEAR DGN2200 — Authenticated OS Command Injection via dnslookup.cgi Enables Root RCE; EOL — Disconnect; HIGH 8.8

CVSS 8.8
CVE-2017-11292

Adobe Flash Player — Type Confusion Exploited as Zero-Day by Black Oasis APT (FinSpy); APSB17-32 Emergency Patch October 2017; Flash EOL December 2020

CVSS 8.8
CVE-2017-6736

Cisco IOS and IOS XE — SNMP Subsystem Buffer Overflow via Crafted SNMP Packets Enables Authenticated RCE; Part of cisco-sa-20170629-snmp; HIGH 8.8

CVSS 8.8
CVE-2017-6737

Cisco IOS and IOS XE — SNMP Subsystem Buffer Overflow (Variant 2) Enables Authenticated RCE or Device Reload; Part of cisco-sa-20170629-snmp; HIGH 8.8

CVSS 8.8
CVE-2017-6738

Cisco IOS and IOS XE — SNMP Subsystem Buffer Overflow (Variant 3) Enables Authenticated RCE or Device Reload; Part of cisco-sa-20170629-snmp; HIGH 8.8

CVSS 8.8
CVE-2017-6739

Cisco IOS and IOS XE — SNMP Subsystem Buffer Overflow (Variant 4) Enables Authenticated RCE or Device Reload; Part of cisco-sa-20170629-snmp; HIGH 8.8

CVSS 8.8
CVE-2017-6740

Cisco IOS and IOS XE — SNMP Subsystem Buffer Overflow (Variant 5) Enables Authenticated RCE or Device Reload; Part of cisco-sa-20170629-snmp; HIGH 8.8

CVSS 8.8
CVE-2017-6743

Cisco IOS and IOS XE — SNMP Subsystem Buffer Overflow (Variant 7) Enables Authenticated RCE; Part of cisco-sa-20170629-snmp; HIGH 8.8

CVSS 8.8
CVE-2017-6744

Cisco IOS — SNMP Subsystem Buffer Overflow (Variant 8) Enables Authenticated RCE or Device Reload; Part of cisco-sa-20170629-snmp; HIGH 8.8

CVSS 8.8
CVE-2017-0037

Microsoft Edge / Internet Explorer — mshtml.dll Type Confusion Enables Remote Code Execution via Malicious Web Page; Patched MS17-007 (March 2017)

CVSS 8.1
CVE-2017-12615

Apache Tomcat — HTTP PUT with Trailing Slash Uploads JSP Web Shell on Windows; Ransomware Delivery; Patched September 2017; Companion CVE-2017-12617 (All Platforms)

CVSS 8.1
CVE-2017-12617

Apache Tomcat — HTTP PUT JSP Upload RCE on All Platforms via Partial PUT Bypass; Companion to CVE-2017-12615 (Windows); Patched October 2017

CVSS 8.1
CVE-2017-0101

Microsoft Windows TxF — Transaction Manager Kernel Memory Corruption Enables SYSTEM Privilege Escalation; Used in Ransomware Chains; Patched MS17-017 (March 2017)

CVSS 7.8
CVE-2017-0001

Microsoft Windows GDI — Kernel Use-After-Free Enables Local Privilege Escalation to SYSTEM; Patched MS17-013 (March 2017)

CVSS 7.8
CVE-2017-0261

Microsoft Office — EPS Filter UAF Zero-Day Exploited by APT28/Turla Before May 2017 Patch; Chained with Win32k LPE CVE-2017-0263 for Sandbox Escape

CVSS 7.8
CVE-2017-11826

Microsoft Office — OOXML Document Object Memory Corruption Exploited in Targeted Attacks; Patched October 2017 Patch Tuesday

CVSS 7.8
CVE-2017-8540

Microsoft Malware Protection Engine (MsMpEng) — Scanning Malicious File Triggers OOB Write Memory Corruption and SYSTEM RCE; HIGH 7.8; Patched May 2017

CVSS 7.8
CVE-2017-12231

Cisco IOS — NAT Implementation Flaw Enables Unauthenticated Remote DoS; Part of September 2017 Cisco Advisory Bundle; Nation-State Network Infrastructure Targeting

CVSS 7.5
CVE-2017-12233

Cisco IOS — CIP Implementation Flaw Causes Unauthenticated Remote DoS; ICS/OT Network Risk; September 2017 Advisory Bundle

CVSS 7.5
CVE-2017-12234

Cisco IOS — Second CIP DoS Vulnerability; Unauthenticated Remote Device Reload; September 2017 Advisory Bundle; ICS/OT Network Exposure

CVSS 7.5
CVE-2017-12235

Cisco IOS Industrial Ethernet Switches — PROFINET PN-DCP Flaw Enables Unauthenticated Remote DoS; ICS/OT Manufacturing Risk; September 2017 Advisory Bundle

CVSS 7.5
CVE-2017-12237

Cisco IOS/IOS XE — IKEv2 Flaw Enables Unauthenticated Remote DoS via CPU Exhaustion or Reload; VPN Infrastructure Targeting; September 2017 Advisory Bundle

CVSS 7.5
CVE-2017-6627

Cisco IOS and IOS XE — UDP Processing Input Queue Wedge Causes Interface Denial-of-Service; HIGH 7.5; Patched September 2017

CVSS 7.5
CVE-2017-0213

Microsoft Windows — COM Aggregate Marshaler Registry Hijack Enables LPE to SYSTEM; Ransomware Post-Exploitation; Patched May 2017

CVSS 7.3

February 2022

December 2021

November 2021

CVE-2017-0143

Microsoft Windows SMBv1 — EternalRomance: NSA Equation Group SMBv1 RCE Exposed by Shadow Brokers; WannaCry and NotPetya Ransomware Propagation; Patched MS17-010

CVSS 8.8
CVE-2017-6327

Symantec Symantec Messaging Gateway — Symantec Messaging Gateway Remote Code Execution Vulnerability

CVSS 8.8
CVE-2017-9822

DotNetNuke (DNN) CMS — DNNPersonalization Cookie .NET BinaryFormatter Deserialization Enables Authenticated RCE; Ransomware Used; HIGH 8.8; Patched July 2017

CVSS 8.8
CVE-2017-9805

Apache Struts REST Plugin — XStream XML Deserialization Without Type Filtering Enables Unauthenticated RCE via Crafted XML Request; S2-052; HIGH 8.1; Patched September 2017

CVSS 8.1
CVE-2017-0199

Microsoft Office/WordPad — RTF OLE2 HTA Zero-Day: Moniker Download-and-Execute Before April 2017 Patch; Used by Carbanak, APT32, Dridex; Ransomware Delivery

CVSS 7.8
CVE-2017-11774

Microsoft Outlook — Home Page Feature Enables RCE via Malicious URL; APT33 Persistence Mechanism; Patched October 2017 Patch Tuesday

CVSS 7.8
CVE-2017-11882

Microsoft Office — 17-Year-Old Equation Editor (EQNEDT32.EXE) Stack Overflow; No ASLR/DEP; Massively Exploited for RAT/Ransomware Delivery Globally; Patched November 2017

CVSS 7.8
CVE-2017-16651

Roundcube Webmail — Insufficient Attachment Plugin Input Validation Enables Authenticated Arbitrary File Read on Webmail Server; HIGH 7.8; Fixed November 2017

CVSS 7.8
CVE-2017-8759

Microsoft .NET Framework — WSDL Code Injection via Crafted SOAP Response Enables RCE When Processing Malicious Document; HIGH 7.8; Patched September 2017

CVSS 7.8

Medium 6

May 2022

March 2022