CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Exchange. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
Original NVD Description
Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by Newforma Project Center Server (NPCS), so a compromised NIX system can be used to attack an associated NPCS system. To mitigate this vulnerability, restrict network access to the '/remoteweb/remote.rem' endpoint, for example using the IIS URL Rewrite Module.
Related CVEs
Other vulnerabilities affecting the same vendor(s)