Top 10 winner
Exploiting Hardened .NET Deserialization
Shows how to keep exploiting .NET deserialization sinks that vendors hardened with type allow-lists and binders: new gadgets in product code and third-party libraries, arbitrary getter-call chains, and abuse of insecure serialization to reach remote code execution, arbitrary file read and environment-variable leaks, demonstrated on SolarWinds Platform and Delta InfraSuite.
Record
- Researcher
- Piotr Bazydło
- Published by
- Trend Micro Zero Day Initiative
- Format
- Whitepaper
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host.