CVE-2022-21167
HIGHMasuit.Tools.Core - Arbitrary Code Execution via BinaryFormatter Payload
Title source: manualDescription
All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-DOTNET-MASUITTOOLSCORE-2316875
Scores
CVSS v3
7.5
EPSS
0.0091
EPSS Percentile
76.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (2)
ldqk/masuit.tools
nuget/Masuit.Tools.Core
0NuGet
Published
May 01, 2022
Tracked Since
Feb 18, 2026