« Back to list

CVE-2017-5176

Status: ModifiedHigh (7)—

A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-5176",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 1.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Rockwell Automation Connected Components Workbench",
          "versions": [
            {
              "status": "affected",
              "version": "Rockwell Automation Connected Components Workbench"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-05-19T03:29:00.293",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/97000",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-047-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/97000",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-047-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema de secuestro de DLL en Connected Components Workbench (CCW) de Rockwell Automation. Están afectadas las siguientes versiones: Connected Components Workbench - Developer Edition, versión v9.01.00 y anteriores a: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CC y Connected Components Workbench - Edición Estándar Gratuita (todos los idiomas compatibles), versión v9.01.00 y anteriores. Ciertos bibliotecas DLL incluidas con las versiones de software de CCW pueden ser secuestradas para permitir a un atacante alcanzar derechos sobre la computadora personal afectada de la víctima. Dichos derechos de acceso pueden estar en el mismo nivel de privilegios o potencialmente en un nivel más alto al de la cuenta de usuario comprometida, incluyendo los privilegios de administrador de computadora."
    }
  ],
  "lastModified": "2026-06-17T01:20:05.993",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rockwellautomation:connected_components_workbench:*:*:*:*:developer:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D30E0FF5-DFC8-4A9E-AC5E-A989607E2419",
              "versionEndIncluding": "9.01.00"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevdee:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "669BA851-4DD0-498B-8775-4C9529CAF06C"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevene:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "589025A2-B3B1-4FFC-A6F2-9D6E3A976E3E"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevese:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "49295F0C-B90A-46BF-AC22-723743237A3D"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevfre:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5B41A881-8DAA-43E3-934E-4500C8815666"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevite:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3D2366F9-803F-433A-8712-1E328D03FFAF"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevpte:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "68B1539D-19C2-4048-8904-C0B6D60E34D6"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevzhe:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C5654863-5B85-4EE3-96A2-8624407BD9FC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rockwellautomation:connected_components_workbench:*:*:*:*:free_standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AE5B4DF-E10A-42DB-B9F3-E9D292281235",
              "versionEndIncluding": "9.01.00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}