| CVE ID | |
| CVSS SCORE | 5.0, AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
| AFFECTED VENDORS |
Microsoft |
| AFFECTED PRODUCTS |
.NET |
| VULNERABILITY DETAILS |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft ASP.NET. Authentication may be required to exploit this vulnerability depending upon configuration. Additionally, specific configuration is required. The specific flaw exists within the handling of SOAP web service definitions. A crafted uploaded file can bypass restrictions on code execution. An attacker can leverage this vulnerability to execute code in the context of the service account. |
| ADDITIONAL DETAILS |
06/25/25 - ZDI reported the vulnerability to the vendor -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product. |
| DISCLOSURE TIMELINE |
|
| CREDIT | Anonymous |