CVE Tools

SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL

watchTowr LabsBy Piotr Bazydlo (@chudyPB)26 min read

PoC public.NET FrameworkBarracuda Service Center RMM
Read at watchTowr Labs

Below is the opening; the full story is at watchTowr Labs.

From watchTowr Labs

Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025).

Weeeeeeeee. Before then, we want to clear the decks and see how much research we can publish.

This year at Black Hat Europe, Piotr Bazydlo presented “SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL”. This research ultimately led to the identification of new primitives in the .NET Framework that, while Microsoft decided deserved DONOTFIX (repeatedly), were successfully weaponized against enterprise-grade appliances to achieve Remote Code Execution.…

Continue at watchTowr Labs

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store