Vulnerability record · CVE-2017-9822 · published 20 July 2017
CVE-2017-9822: DNN (DotNetNuke) cookie deserialization remote code execution
DDnnsoftware · Dotnetnuke
DNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) reachable over the network, and it is listed in CISA's Known Exploited Vulnerabilities catalog with documented ransomware campaign use.
Description
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a network-reachable remote code execution flaw listed in CISA KEV with known ransomware use and a very high EPSS score.
What it is
DNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) reachable over the network, and it is listed in CISA's Known Exploited Vulnerabilities catalog with documented ransomware campaign use.
Impact
An attacker who can reach the site can execute arbitrary code on the server, leading to full compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network via a crafted cookie; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N). No further detail on the exact endpoint is given in the record.
Exploitation
CISA KEV lists it as exploited, including known ransomware campaign use, and EPSS is very high (0.94789, 99.855th percentile). Public exploit code is referenced (Packet Storm), so exploitation is active and well understood.
What to do
- Upgrade DNN to 9.1.1 or later per vendor instructions.
- If immediate upgrade is not possible, restrict or block external access to the DNN site and apply vendor-recommended workarounds.
- Rotate any secrets, machine keys and credentials that may have been exposed on affected hosts.
- Monitor and restrict outbound traffic from DNN servers to limit post-exploitation activity.
- Verify no unauthorized web shells or modified files remain after patching.
Detection
- Inspect web server and application logs for anomalous or malformed cookie values sent to DNN endpoints.
- Hunt for unexpected child processes spawned by the web server (w3wp.exe) or unusual command execution.
- Monitor for new or modified files under the DNN web root, especially executable or script files.
- Alert on outbound connections from DNN hosts to unfamiliar external addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-9822 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "DotNetNuke (DNN) Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.dnnsoftware.com/community/security/security-center | ProductVendor Advisory |
| http://www.securityfocus.com/bid/102213 | Broken LinkThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.dnnsoftware.com/community/security/security-center | ProductVendor Advisory |
| http://www.securityfocus.com/bid/102213 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9822 | US Government Resource |
Track CVE-2017-9822 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9822), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.