Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-9046

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Pegasus Mail(又名Pmail)是一款电子邮件客户端,可使用在Microsoft Windows操作系统下。 Pegasus Mail 4.72 build 572版本中的winpm-32.exe文件存在安全漏洞。攻击者可借助特制的ssgp.dll文件利用该漏洞执行代码。

AI Predicted 7.8 Difficulty: Easy EPSS 0.57% · P45
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-9046

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a mailto: link on a remote web page triggers the attack.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Pegasus Mail 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pegasus Mail(又名Pmail)是一款电子邮件客户端,可使用在Microsoft Windows操作系统下。 Pegasus Mail 4.72 build 572版本中的winpm-32.exe文件存在安全漏洞。攻击者可借助特制的ssgp.dll文件利用该漏洞执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2017-9046

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-9046

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2017-9046 (1)

Same Patch Batch · n/a · 2017-05-21 · 23 CVEs total

CVE-2017-9101 PlaySMS 安全漏洞
CVE-2017-9100 D-Link DIR-600M 安全漏洞
CVE-2017-9024 Secure Bytes Secure Cisco Auditor Secure Bytes Cisco Configuration Manager TFTP Server 路径遍
CVE-2017-7620 MantisBT 跨站请求伪造漏洞
CVE-2017-9116 LIM OpenEXR 数字错误漏洞
CVE-2017-9115 LIM OpenEXR 数字错误漏洞
CVE-2017-9114 LIM OpenEXR 数字错误漏洞
CVE-2017-9113 LIM OpenEXR 数字错误漏洞
CVE-2017-9112 LIM OpenEXR 数字错误漏洞
CVE-2017-9111 LIM OpenEXR 数字错误漏洞
CVE-2017-9110 LIM OpenEXR 数字错误漏洞
CVE-2017-9138 腾达FH1202、F1202和F1200路由器安全漏洞
CVE-2014-9970 Jasypt 安全漏洞
CVE-2017-9119 PHP 安全漏洞
CVE-2017-9137 Ceragon FibeAir IP-10 wireless radios 安全漏洞
CVE-2017-9136 Mimosa Client Radios 安全漏洞
CVE-2017-9135 Mimosa Client Radios和Mimosa Backhaul Radios 安全漏洞
CVE-2017-9134 Mimosa Client Radios和Mimosa Backhaul Radios 信息泄露漏洞
CVE-2017-9133 Mimosa Client Radios和Mimosa Backhaul Radios 安全漏洞
CVE-2017-9132 多款Mimosa产品安全漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-9046

No comments yet


Leave a comment