Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-56158-.NET-Framework-RCE-PoC-Exploit — Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner, and JSON report output. | Kitploit
Tools/GitHubGitHub/sam00/cve-2026-56158-.net-framework-rce-poc-exploit
Vulnerability ScannersPayload GenerationStatic Code Analysis (SAST)Vulnerability AnalysisExploitationWeb Application ExploitationPayload Development
GitHub
sam00/cve-2026-56158-.net-framework-rce-poc-exploit

CVE-2026-56158-.NET-Framework-RCE-PoC-Exploit

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner, and JSON report output.

View Repository
1251 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-56158 — .NET Framework Remote Code Execution (RCE) PoC Exploit

Critical (CVSS 9.8) — Deserialization of Untrusted Data (CWE-502) in Microsoft .NET Framework & .NET Runtime Patched: July 14, 2026 | Attributed to: Positive Technologies (PT-2026-60174)


Table of Contents

  • Overview
  • Vulnerability Details
  • Affected Versions
  • Attack Vectors
  • Exploit Architecture
  • File Structure
  • Installation
  • Step-by-Step Usage
  • Testing
  • Detection & Hardening
  • Mitigation
  • References
  • Disclaimer
  • License

Overview

CVE-2026-56158 is a critical remote code execution vulnerability in Microsoft .NET Framework and .NET runtime. The flaw exists in the unsafe deserialization of untrusted data (CWE-502) — when a .NET application uses legacy serializers (BinaryFormatter, NetDataContractSerializer, SoapFormatter, ObjectStateFormatter) or Json.NET with TypeNameHandling.All/Auto, an unauthenticated remote attacker can deliver a crafted serialized payload that triggers arbitrary code execution upon deserialization.

The vulnerability carries a CVSS 3.1 base score of 9.8 Critical with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning:

  • Attack Vector: Network (no physical access needed)
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Impact: Complete compromise of Confidentiality, Integrity, and Availability

Microsoft released security updates on July 14, 2026 as part of the monthly Patch Tuesday cycle.


Vulnerability Details

FieldValue
CVE IDCVE-2026-56158
Title.NET Framework Remote Code Execution Vulnerability
CVSS 3.19.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVSS 2.07.5 High (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWECWE-502 (Deserialization of Untrusted Data)
PublishedJuly 14, 2026
PatchedJuly 14, 2026
DiscovererPositive Technologies (PT-2026-60174)
EPSSNot scored yet
CISA KEVNot listed

Root Cause

The .NET runtime's legacy serializers reconstruct arbitrary object types from serialized streams without validating the type or content. When an attacker controls the serialized input, they can direct the deserializer to instantiate unexpected types whose constructors, callbacks, or property setters execute arbitrary code — a classic deserialization gadget chain attack.

The vulnerability affects multiple serialization mechanisms:

  1. BinaryFormatter — Binary stream with type metadata; TypeConfuseDelegate gadget chain delegates to Process.Start
  2. NetDataContractSerializer — XML format that includes .NET type information; allows direct type instantiation
  3. SoapFormatter — SOAP XML envelope with CLR type references; ProcessStartInfo embedded in SOAP body
  4. ObjectStateFormatter — ASP.NET ViewState binary format; Process.Start via ViewState field
  5. Json.NET (Newtonsoft.Json) — JSON with $type metadata when TypeNameHandling.All/Auto is enabled; ObjectDataProvider gadget calls Process.Start

Affected Versions

ProductVulnerable RangeFixed VersionKB Article
.NET 8.08.0.0 – 8.0.288.0.29KB5100998
.NET 9.09.0.0 – 9.0.179.0.18KB5100998
.NET 10.010.0.0 – 10.0.910.0.10KB5101001
.NET Framework 3.5All pre-patchPatchedKB5100985
.NET Framework 4.6.2–4.7.2All pre-patchPatchedKB5100991
.NET Framework 4.8All pre-patchPatchedKB5101011
.NET Framework 4.8.1All pre-patchPatchedKB5101002
Visual Studio 2022 (17.12)Pre-patch17.12.x—
Visual Studio 2022 (17.14)Pre-patch17.14.x—
Visual Studio 2026 (18.7)Pre-patch18.7.x—

Alpine Linux packages:

  • dotnet8-runtime < 8.0.29-r0
  • dotnet9-runtime < 9.0.18-r0
  • dotnet10-runtime < 10.0.10-r0

Attack Vectors

This PoC exploit generates and delivers payloads via 5 different deserialization attack formats:

1. BinaryFormatter (TypeConfuseDelegate Gadget)

Serialized Stream → BinaryFormatter.Deserialize() → TypeConfuseDelegate
  → Process.Start("cmd.exe", "/c calc.exe") → RCE
  • Format: Binary (.NET serialized stream)
  • Content-Type: application/octet-stream
  • Delivery: HTTP POST body, file
  • Gadget: ActivitySurrogateSelector+ObjectSurrogate → TypeConfuseDelegate → Process.Start

2. NetDataContractSerializer

XML with type info → NetDataContractSerializer.ReadObject()
  → ProcessStartInfo instantiation → Process.Start → RCE
  • Format: XML with embedded .NET type information
  • Content-Type: application/octet-stream or text/xml
  • Delivery: HTTP POST body, WCF endpoint

3. SoapFormatter

SOAP envelope → SoapFormatter.Deserialize()
  → ProcessStartInfo in SOAP body → Process.Start → RCE
  • Format: SOAP XML envelope with CLR type references
  • Content-Type: text/xml
  • Delivery: WCF/ASMX SOAP endpoint

4. ObjectStateFormatter (ViewState)

ViewState binary → ObjectStateFormatter.Deserialize()
  → Process.Start via ViewState field → RCE
  • Format: Binary (ASP.NET ViewState format)
  • Content-Type: application/octet-stream
  • Delivery: HTTP POST __VIEWSTATE field

5. Json.NET (TypeNameHandling.All)

JSON with $type → JsonConvert.DeserializeObject<T>(json, TypeNameHandling.All)
  → ObjectDataProvider.MethodName = "Start" → Process.Start → RCE
  • Format: JSON with $type metadata
  • Content-Type: application/json
  • Delivery: REST API endpoint with TypeNameHandling.All or Auto

Exploit Architecture

┌─────────────────────────────────────────────────────────────────────┐
│                         exploit.py                                   │
├─────────────────────────────────────────────────────────────────────┤
│                                                                      │
│  ┌──────────────┐   ┌───────────────┐   ┌───────────────────────┐  │
│  │ PayloadGen   │   │ PayloadDeliv  │   │ VulnerabilityScanner  │  │
│  │              │   │               │   │                       │  │
│  │ • BinaryFmt  │   │ • HTTP POST   │   │ • HTTP header check   │  │
│  │ • NetData    │──▶│ • SOAP/WCF   │──▶│ • Endpoint discovery  │  │
│  │ • SoapFmt    │   │ • JSON API    │   │ • ViewState analysis  │  │
│  │ • ObjectState│   │ • File save   │   │ • Version detection   │  │
│  │ • Json.NET   │   │               │   │                       │  │
│  └──────────────┘   └───────────────┘   └───────────────────────┘  │
│         │                   │                      │                 │
│         └───────────────────┼──────────────────────┘                 │
│                             ▼                                        │
│  ┌──────────────┐   ┌──────────────────────────────────────────┐   │
│  │ PayloadList  │   │ Report Generator (JSON)                   │   │
│  │ (Mock .NET)  │   │ • CVE metadata, CVSS, CWE                │   │
│  │              │   │ • Payload hashes (SHA-256)               │   │
│  │ Simulates    │   │ • Delivery results                       │   │
│  │ vulnerable   │   │ • RCE confirmation                       │   │
│  │ deserialization│ │ • References                             │   │
│  └──────────────┘   └──────────────────────────────────────────┘   │
│                                                                      │
└─────────────────────────────────────────────────────────────────────┘

Attack Flow

Download Tool