PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-2290 Microsoft CVE debrief

CVE-2017-2290 is a privilege-escalation issue in Puppet's mcollective-puppet-agent on Windows. In version 1.12.0, a non-administrator user can place an executable that is later run with administrator privileges when "mco puppet" is executed. The issue is fixed in mcollective-puppet-agent 1.12.1, and Puppet Enterprise users are stated to be unaffected.

Vendor
Microsoft
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-03
Original CVE updated
2026-05-13
Advisory published
2017-03-03
Advisory updated
2026-05-13

Who should care

Windows administrators and operators using mcollective-puppet-agent 1.12.0, especially environments that run "mco puppet" with elevated privileges. Teams responsible for Puppet-managed Windows endpoints should verify they are not on the vulnerable plugin version.

Technical summary

The NVD record classifies this as CWE-732 and gives it CVSS 3.1 8.8 HIGH (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerable condition is limited to mcollective-puppet-agent 1.12.0 on Windows: a non-admin user can create an executable that is executed with administrator privileges on the next "mco puppet" run. The vendor advisory says the issue is resolved in 1.12.1 and that Puppet Enterprise users are not affected.

Defensive priority

High. This is an administrator-privilege execution issue on a specific Windows plugin version and should be patched promptly wherever the vulnerable component is present.

Recommended defensive actions

  • Upgrade mcollective-puppet-agent to version 1.12.1 or later.
  • Inventory Windows systems for mcollective-puppet-agent 1.12.0 and prioritize those hosts for remediation.
  • Confirm whether any deployments are Puppet Enterprise; the vendor states those users are not affected by this CVE.
  • Use the official vendor advisory and NVD entry to validate the affected scope before closure.

Evidence notes

The CVE description, NVD record, and Puppet advisory all align on the affected component and scope: Windows installations of mcollective-puppet-agent 1.12.0, non-administrator-created executable execution with administrator privileges on the next "mco puppet" run, and remediation in 1.12.1. NVD lists the vulnerable CPE for puppet:mcollective-puppet-agent:1.12.0 and CWE-732, and cites the Puppet vendor advisory plus a SecurityFocus BID entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-2290 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-2290

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-2290 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2290

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.