PatchSiren cyber security CVE debrief
CVE-2017-2290 Microsoft CVE debrief
CVE-2017-2290 is a privilege-escalation issue in Puppet's mcollective-puppet-agent on Windows. In version 1.12.0, a non-administrator user can place an executable that is later run with administrator privileges when "mco puppet" is executed. The issue is fixed in mcollective-puppet-agent 1.12.1, and Puppet Enterprise users are stated to be unaffected.
- Vendor
- Microsoft
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
Windows administrators and operators using mcollective-puppet-agent 1.12.0, especially environments that run "mco puppet" with elevated privileges. Teams responsible for Puppet-managed Windows endpoints should verify they are not on the vulnerable plugin version.
Technical summary
The NVD record classifies this as CWE-732 and gives it CVSS 3.1 8.8 HIGH (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerable condition is limited to mcollective-puppet-agent 1.12.0 on Windows: a non-admin user can create an executable that is executed with administrator privileges on the next "mco puppet" run. The vendor advisory says the issue is resolved in 1.12.1 and that Puppet Enterprise users are not affected.
Defensive priority
High. This is an administrator-privilege execution issue on a specific Windows plugin version and should be patched promptly wherever the vulnerable component is present.
Recommended defensive actions
- Upgrade mcollective-puppet-agent to version 1.12.1 or later.
- Inventory Windows systems for mcollective-puppet-agent 1.12.0 and prioritize those hosts for remediation.
- Confirm whether any deployments are Puppet Enterprise; the vendor states those users are not affected by this CVE.
- Use the official vendor advisory and NVD entry to validate the affected scope before closure.
Evidence notes
The CVE description, NVD record, and Puppet advisory all align on the affected component and scope: Windows installations of mcollective-puppet-agent 1.12.0, non-administrator-created executable execution with administrator privileges on the next "mco puppet" run, and remediation in 1.12.1. NVD lists the vulnerable CPE for puppet:mcollective-puppet-agent:1.12.0 and CWE-732, and cites the Puppet vendor advisory plus a SecurityFocus BID entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2290 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2290
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2290 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2290
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://puppet.com/security/cve/cve-2017-2290
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.