CVE-2017-5644
CVE-2017-5644
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 4.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Mar 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Affected products
Apache Software Foundation · Apache POIWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →