New “SOAPwn” .NET Vulnerabilities Expose Barracuda, Ivanti and Microsoft Appliances to RCE Attack
ID: b3dce682-c15b-5305-9a9c-9ffd78aafcdc
STIX ID: report--b3dce682-c15b-5305-9a9c-9ffd78aafcdc
Feed Name: cybersecurityNews.com
SOAPwn is a class of vulnerabilities in .NET SOAP HTTP client proxy implementations that allow attacker-controlled WSDL/URL input to change request schemes (including file:// and UNC), enabling NTLM relay, arbitrary file writes to web-accessible paths, and full remote code execution; multiple enterprise products (Barracuda Service Center RMM, Ivanti Endpoint Manager, Umbraco 8, PowerShell, SSIS) are affected, with at least one tracked CVE (CVE-2025-34392) and vendor fixes or advisories, while Microsoft has classified the issue as an application-layer problem rather than fixing the framework itself.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
