CVE Feed

    Dashboard / CVE / CVE-2017-13779

    CVE-2017-13779

    GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example, a local user could create VBScript code for a TCP reverse shell, and use that later for Remote Command Execution.

    Published:Sep 14, 2017
    Last Modified:Apr 20, 2025
    EPS:Sep 14, 2017
    EPSS Score:0.00379
    CVSS Score:7.8

    Affected Products

    Vendor
    Gstn
    Product
    India Goods And Services Tax Network Offline Utility Tool

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High