Critical SOAPwn Flaw Enables Remote Code Execution in .NET Apps

Critical SOAPwn Vulnerability in .NET Framework Enables Remote Code Execution via Malicious WSDL Files and HTTP Client Proxies

  • A critical vulnerability named SOAPwn affects the .NET Framework, enabling remote code execution in enterprise applications.
  • The flaw abuses Web Services Description Language (WSDL) imports and HTTP client proxies to manipulate Simple Object Access Protocol (SOAP) message handling.
  • Exploitable products include Barracuda Service Center RMM and Ivanti Endpoint Manager, with patches released to address the issue.
  • Microsoft did not issue a fix, citing the problem as application-side behavior requiring user caution when handling untrusted input.

New research revealed security weaknesses in the .NET Framework that allow attackers to execute code remotely by exploiting mishandling of Simple Object Access Protocol (SOAP) messages. The findings were disclosed publicly on December 10, 2025, during a presentation at the Black Hat Europe security conference in London.

- Advertisement -

The vulnerability, tracked as SOAPwn, targets how Web Services Description Language (WSDL) files and HTTP client proxies interact in .NET-based applications. Attackers can supply malicious WSDL files that dynamically generate SOAP clients, exploiting these to write arbitrary files or deploy web shells. This enables remote code execution on affected systems.

Products impacted by this flaw include Barracuda Service Center RMM and Ivanti Endpoint Manager (EPM). Researchers also noted the broad usage of .NET means many other vendors might be at risk. Full details were presented by security researcher Piotr Bazydlo, who explained the issue arises from the unsafe handling of URLs passed as parameters to HTTP client proxies, such as those beginning with “file://” or containing Universal Naming Convention (UNC) paths.

These manipulated URLs can cause the vulnerable SOAP clients to write SOAP requests directly to attacker-controlled file shares, potentially capturing network authentication challenges or overwriting critical files. More advanced exploitation uses the ServiceDescriptionImporter class, which does not validate URLs used to generate client proxies. This can allow attackers to drop fully functional web shells or PowerShell scripts remotely.

Since the vulnerability stems from how applications consume untrusted input rather than a defect purely in the framework, Microsoft declined to patch it after responsible disclosure in March 2024 and July 2025. The company advised users to avoid loading untrusted WSDL files or generating proxies that run code from unverified sources.

- Advertisement -

Remediations have been offered by affected vendors. Barracuda Service Center RMM addressed the flaw in version 2025.1.1 (CVE-2025-34392, CVSS score 9.8), while Ivanti EPM released a fix in version 2024 SU4 SR1 (CVE-2025-13659, CVSS score 8.8). The vulnerability illustrates how expected framework behavior might lead to critical security risks such as arbitrary code execution and NTLM challenge capture.

“It is possible to make SOAP proxies write SOAP requests into files rather than sending them over HTTP,” Bazydlo stated. “In many cases, this leads to remote code execution through webshell uploads or PowerShell script uploads. The exact impact depends on the application using the proxy classes.”

More technical details are available via the WatchTowr Labs report, and the Black Hat Europe presentation.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

DeFi surge, three hacks and MEV bot returns majority funds!!

Three separate DeFi attacks this week drained millions and prompted on-chain recovery efforts.Makina reported...

BitGo shares tumble 22% after $212M IPO; dip below $15 at 2B

BitGo shares fell nearly 22% on the second trading day after its IPO debut...

Intel Slides 17% After Q1 Guidance Miss; Supply Constraints.

INTC shares fell more than 17% on Friday after a quarterly report and weak...

Gold’s FOMO Drains Bitcoin: Prices Falling, Metals Rise Soon

The author argues that Bitcoin prices are likely to weaken because fewer groups need...

Paradex refunds $650,000 to 200 users after error in markets

Paradex refunded $650,000 to roughly 200 users after a maintenance error caused unintended liquidations.The...
- Advertisement -

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!