PatchSiren cyber security CVE debrief
CVE-2017-2290 Microsoft CVE debrief
CVE-2017-2290 is a privilege-escalation issue in Puppet's mcollective-puppet-agent on Windows. In version 1.12.0, a non-administrator user can place an executable that is later run with administrator privileges when "mco puppet" is executed. The issue is fixed in mcollective-puppet-agent 1.12.1, and Puppet Enterprise users are stated to be unaffected.
- Vendor
- Microsoft
- Product
- CVE-2017-2290
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
Windows administrators and operators using mcollective-puppet-agent 1.12.0, especially environments that run "mco puppet" with elevated privileges. Teams responsible for Puppet-managed Windows endpoints should verify they are not on the vulnerable plugin version.
Technical summary
The NVD record classifies this as CWE-732 and gives it CVSS 3.1 8.8 HIGH (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerable condition is limited to mcollective-puppet-agent 1.12.0 on Windows: a non-admin user can create an executable that is executed with administrator privileges on the next "mco puppet" run. The vendor advisory says the issue is resolved in 1.12.1 and that Puppet Enterprise users are not affected.
Defensive priority
High. This is an administrator-privilege execution issue on a specific Windows plugin version and should be patched promptly wherever the vulnerable component is present.
Recommended defensive actions
- Upgrade mcollective-puppet-agent to version 1.12.1 or later.
- Inventory Windows systems for mcollective-puppet-agent 1.12.0 and prioritize those hosts for remediation.
- Confirm whether any deployments are Puppet Enterprise; the vendor states those users are not affected by this CVE.
- Use the official vendor advisory and NVD entry to validate the affected scope before closure.
Evidence notes
The CVE description, NVD record, and Puppet advisory all align on the affected component and scope: Windows installations of mcollective-puppet-agent 1.12.0, non-administrator-created executable execution with administrator privileges on the next "mco puppet" run, and remediation in 1.12.1. NVD lists the vulnerable CPE for puppet:mcollective-puppet-agent:1.12.0 and CWE-732, and cites the Puppet vendor advisory plus a SecurityFocus BID entry.
Official resources
-
CVE-2017-2290 CVE record
CVE.org
-
CVE-2017-2290 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Published on 2017-03-03T15:59:00.647Z. NVD was last modified on 2026-05-13T00:24:29.033Z; use the CVE publication date for issue timing.