logo

XOML Workflow Protection Bypass Vulnerability

ID: 198e53b0-7c82-5bf6-bec5-9b9bfd59be57

STIX ID: report--198e53b0-7c82-5bf6-bec5-9b9bfd59be57

Feed Name: NCC Research

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-07-31

...
...

This advisory details a critical deserialization vulnerability in the .NET Framework Workflow/XOML processing (CVE-2018-8421) that allows authenticated users to execute code on servers (notably SharePoint) despite /nocode and /checktypes protections. Multiple PoCs are provided demonstrating techniques (ObjectDataProvider, ProcessStartInfo/ObjectInstance, WorkflowDesigner, AssemblyInstaller) and Microsoft published a patch in September 2018 to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.