CVE-2025-59710

An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:*

History

09 Apr 2026, 00:46

Type Values Removed Values Added
First Time Kovai
Kovai biztalk360
CWE CWE-434
CPE cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://www.synacktiv.com/en/advisories/remote-code-execution-from-any-domain-account-in-biztalk360 - () https://www.synacktiv.com/en/advisories/remote-code-execution-from-any-domain-account-in-biztalk360 - Third Party Advisory

03 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 15:16

Updated : 2026-04-09 21:16


NVD link : CVE-2025-59710

Mitre link : CVE-2025-59710

CVE.ORG link : CVE-2025-59710


JSON object : View

Products Affected

kovai

  • biztalk360
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type