Deserialization Vulnerability in JetBrains Software Products
CVE-2018-14878
7.8HIGH
What is CVE-2018-14878?
JetBrains dotPeek prior to version 2018.2 and ReSharper Ultimate prior to version 2018.1.4 are susceptible to a serious vulnerability that allows attackers to execute arbitrary code through the deserialization of untrusted data. This occurs when a compiled .NET object, such as a DLL or EXE file, is decompiled using a specific file, enabling malicious users to exploit the system. It is crucial for users of these software products to upgrade to the latest versions to protect against this security flaw.