CVE-2025-59710
EUVD-2025-20920503.04.2026, 15:16
An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kovai | biztalk360 | 𝑥 < 11.6.3963.2611 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration