Discovering a Deserialization Vulnerability in LINQPad
ID: 1a1f7b87-f21d-5c35-b8e5-cb23493d2284
STIX ID: report--1a1f7b87-f21d-5c35-b8e5-cb23493d2284
Feed Name: TrustedSec blog
Threat Score
A researcher found a deserialization vulnerability in LINQPad Pro (v5.48.00) where BinaryFormatter.Deserialize processes a writable per-user cache file, enabling RCE via a crafted ysoserial payload; the issue was responsibly disclosed and patched in LINQPad 5.52.01 (CVE-2024-53326).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
