CVE-2025-35050 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbit…
Critical CVSS: 9.3

CVE-2025-35050

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by Newforma Project Center Server (NPCS), so a compromised NIX system can be used to attack an associated NPCS system. To mitigate this vulnerability, restrict network access to the '/remoteweb/remote.rem' endpoint, for example using the IIS URL Rewrite Module.
Vendor
Newforma
Product
Project Center
CWE
CWE-306
Yayın Tarihi
2025-10-09 21:15:35
Güncelleme
2026-01-09 18:19:59
Source Identifier
9119a7d8-5eab-497f-8521-727c672e3725
KEV Date Added
-

Kategoriler

Referanslar