New research has uncovered exploitable primitives in the .NET Framework that could be used against enterprise-grade applications to achieve remote code execution. WatchTowr Labs, which has codenamed the vulnerability as .NET SOAPwn, reported that the issue affects Barracuda Service Center RMM, Ivanti Endpoint Manager (EPM), and Umbraco 8.However, the number of affected vendors is likely to be higher given the widespread use of .NET.

The findings were presented by WatchTowr security researcher Piotr Bazydlo at the Black Hat Europe security conference in London.
See also: WinRAR vulnerability CVE-2025-6218 under active attack
SOAPwn allows attackers to exploit Web Services Description Language (WSDL) imports and HTTP client proxies to execute arbitrary code in .NET-based products due to errors in the way they handle Simple Object Access Protocol (SOAP) messages.
"It is usually exploitable via SOAP clients, especially if they are dynamically generated from WSDL controlled by the attacker," Bazydlo said.
As a result, the HTTP client proxies can be manipulated to use file system handlers and achieve arbitrary file writes by passing a URL like "file://" code execution. To make matters worse, it can be used to overwrite existing files, as the attacker controls the full write path.

In a hypothetical attack scenario, a threat actor could exploit this behavior to provide a Universal Naming Convention (UNC) path (e.g., “file://attacker.server/poc/poc”) and cause the SOAP request to be written to an SMB share under their control. This could allow an attacker to capture the NTLM challenge and decode it.
See also: North Korean hackers exploit React2Shell to deploy EtherRAT
The research also found that a more powerful exploit can be used in applications that generate HTTP client proxies from WSDL files using the ServiceDescriptionImporter class (taking advantage of the fact that it does not validate the URL used by the generated HTTP client proxy).
In this technique, an attacker can provide a URL pointing to a WSDL file that they control, and achieve remote code execution by dropping a fully functional ASPX web shell or additional payloads such as CSHTML web shells or PowerShell scripts.

Microsoft won't fix .NET SOAPwn vulnerability
After responsible disclosure in March 2024 and July 2025, Microsoft chose not to fix the vulnerability, stating that the issue stems from either an implementation or behavioral issue, and that “users should not engage in untrusted input that can generate and execute code.”
The findings show how expected behavior in a popular framework can become a potential exploit path leading to NTLM relaying or arbitrary file writes. The issue has been addressed in Barracuda Service Center RMM version 2025.1.1 (CVE-2025-34392, CVSS score: 9.8) and Ivanti EPM version 2024 SU4 SR1 (CVE-2025-13659, CVSS score: 8.8).
See also: Exploiting vulnerabilities in Ivanti Connect Secure to distribute MetaRAT
“It is possible to make SOAP proxies write SOAP requests to files instead of sending them over HTTP,” Bazydlo said. “In many cases, this leads to remote code execution via webshell uploads or PowerShell script uploads. The exact impact depends on the application using the proxy classes.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
