Top 10 winner
Exploiting Hardened .NET Deserialization
Exploiting Hardened .NET Deserialization: New Exploitation Ideas and Abuse of Insecure Serialization (Whitepaper)
Shows how to keep exploiting .NET deserialization sinks that vendors hardened with type allow-lists and binders: new gadgets in product code and third-party libraries, arbitrary getter-call chains, and abuse of insecure serialization to reach remote code execution, arbitrary file read and environment-variable leaks, demonstrated on SolarWinds Platform and Delta InfraSuite.
Record
- Document
- Exploiting Hardened .NET Deserialization: New Exploitation Ideas and Abuse of Insecure Serialization (Whitepaper)
- Researcher
- Piotr Bazydło
- Published by
- Trend Micro Zero Day Initiative
- Format
- Whitepaper
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .