logo

Microsoft won’t fix .NET RCE bug affecting slew of enterprise apps, researchers say

ID: f3fafdcf-9b06-5f44-aa7e-81a3f231c7af

STIX ID: report--f3fafdcf-9b06-5f44-aa7e-81a3f231c7af

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-12-10

Date Updated: 2026-04-26

Author: Connor Jones

...
...

*Executive summary:* Security researchers disclosed a flaw in the .NET SoapHttpClientProtocol that allows attackers who can influence service URLs or WSDL imports to force the framework to write SOAP requests to local files (or other protocols), enabling arbitrary file drops and remote code execution chains against vulnerable enterprise products; vendors and Microsoft were notified, some vendors patched affected products while Microsoft initially declined to treat the behavior as a vulnerability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.