CVE-2025-59710

An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Biztalk360 anterior a la versión 11.5. Debido a un control de acceso incorrecto, cualquier usuario puede solicitar la carga de un archivo DLL. Durante la carga, se llama a un método. Un atacante puede crear un DLL malicioso, subirlo al servidor y usarlo para lograr la ejecución remota de código en el servidor.

09 Apr 2026, 00:46

Type Values Removed Values Added
CWE CWE-434
First Time Kovai
Kovai biztalk360
CPE cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://www.synacktiv.com/en/advisories/remote-code-execution-from-any-domain-account-in-biztalk360 - () https://www.synacktiv.com/en/advisories/remote-code-execution-from-any-domain-account-in-biztalk360 - Third Party Advisory

03 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 15:16

Updated : 2026-07-24 21:10


NVD link : CVE-2025-59710

Mitre link : CVE-2025-59710

CVE.ORG link : CVE-2025-59710


JSON object : View

Products Affected

kovai

  • biztalk360
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type