CVE-2019-10068
Kentico Xperience Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 95.07% probability · 100th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-502
- Affected
- kentico/xperience
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-10068
References
- http://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://devnet.kentico.com/download/hotfixes#securityBugs-v12Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://devnet.kentico.com/download/hotfixes#securityBugs-v12Release Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-10068US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.