Microsoft won’t fix .NET RCE bug affecting slew of enterprise apps, researchers say
ID: f3fafdcf-9b06-5f44-aa7e-81a3f231c7af
STIX ID: report--f3fafdcf-9b06-5f44-aa7e-81a3f231c7af
Feed Name: The Register (Security)
*Executive summary:* Security researchers disclosed a flaw in the .NET SoapHttpClientProtocol that allows attackers who can influence service URLs or WSDL imports to force the framework to write SOAP requests to local files (or other protocols), enabling arbitrary file drops and remote code execution chains against vulnerable enterprise products; vendors and Microsoft were notified, some vendors patched affected products while Microsoft initially declined to treat the behavior as a vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
