Deserialization of Untrusted Data
58Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.1epss 89%
from disclosure to weapon0 days
Published on NVDDec 3
metasploitDec 3
exploitation probability
89%top 1% of all CVEs
observed exploitation
nono source reports it
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · AjaxPro.2