Junglewise Threat Intelligence

CVE-2019-10068: Kentico Xperience Deserialization of Untrusted Data Vulnerability

CVE-2019-10068 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Kentico Xperience. Vendors: Kentico.

Executive brief

Kentico Xperience (formerly Kentico CMS) fails to properly validate security headers in its staging service, allowing for the bypass of authentication. An attacker can provide malicious .NET object input that, when deserialized, leads to unauthenticated remote code execution on the hosting server.

Affected products

  • Kentico Xperience (formerly Kentico CMS) 9.x versions; 10.0.x before 10.0.52; 11.0.x before 11.0.48; 12.0.x before 12.0.15

Timeline

  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: disclosed
  • 2020-05-06: other: Public exploit released on Packet Storm Security

Related threats