logo

Hunting Deserialization Vulnerabilities With Claude

ID: 2c62e82b-7b24-50cd-bb20-0adbcfea1f5f

STIX ID: report--2c62e82b-7b24-50cd-bb20-0adbcfea1f5f

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-06-12

Date Updated: 2026-05-01

...
...

This blog post shows how to build an MCP server to let an LLM decompile and analyze .NET assemblies, finds a known unsafe deserialization vulnerability in System.AddIn.dll referenced by AddinUtil.exe, and details generating and debugging a working proof-of-concept exploit (including a pipelineroot attack path that ultimately launches calc.exe), while noting required file-structure conditions and limitations of the exploit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.