An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unrestricted DLL Loading in Biztalk360 | |
| Weaknesses | CWE-285 CWE-94 |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T14:39:54.309Z
Reserved: 2025-09-19T00:00:00.000Z
Link: CVE-2025-59710
No data.
Status : Awaiting Analysis
Published: 2026-04-03T15:16:04.500
Modified: 2026-04-03T16:10:23.730
Link: CVE-2025-59710
No data.
OpenCVE Enrichment
Updated: 2026-04-03T21:17:09Z