Back to Blog

ASP.NET resource files (.RESX) and deserialization issues

I have recently published a blog post via NCC Group’s website about the deserialization issue by abusing the ASP.NET resource files (.resx and .resources extensions). A number of products were exploited and some file uploaders can also be vulnerable to this type of attack.

In addition to this, the advisories can be seen via:

I had also reported the same vulnerability in Telerik justDecompile and JetBrains dotPeek:

Relevant tweets about this:

Previous
Story of my two (but actually three) RCEs in SharePoint in 2018
Next
MS 2018 Q4 – Top 5 Bounty Hunter for 2 RCEs in SharePoint Online