CVE-2017-1129
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 30%
from disclosure to weapon0 days
Published on NVDSep 5
1st PoCAug 31
metasploitAug 31
exploitation probability
30%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
In short
IBM Notes 8.5 and 9.0 can crash if a user clicks a malicious link, forcing them to restart the application. This is a denial of service that disrupts work.
Technical detail
A malicious link can trigger a denial of service condition in IBM Notes 8.5 and 9.0, causing the client to hang and become unresponsive. The attack vector is user interaction (clickable link), requiring social engineering to convince the user to click the malicious URL. The impact is application unavailability.
Summary generated and translated by AI from the official description.
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. IBM X-Force ID: 121370.
public PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/42602exploitdbwww.exploit-db.com/exploits/42969unverifiedcve_referencewww.exploit-db.com/exploits/42602/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.