Security researcher Soroush Dalili disclosed multiple remote code execution paths affecting SharePoint and related Microsoft technologies, tying them to unsafe deserialization in workflow handling and ASP.NET resource processing. Two SharePoint Workflow issues were identified in 2018, including CVE-2018-8284 and CVE-2018-8421, with one described as a workflow protection bypass and the other as a deserialization flaw in the .NET Framework that affected SharePoint deployments, including on-premises systems. A separate report showed that compiling attacker-supplied XOML workflow files could trigger code execution despite safeguards such as /nocode and /checktypes, using gadget chains such as ObjectDataProvider to reach dangerous methods like System.Diagnostics.Process.Start() in some SharePoint scenarios.
Dalili also linked SharePoint exposure to a broader class of ASP.NET .resx and .resources deserialization vulnerabilities that could lead to code execution across multiple Microsoft products and developer tools. That research was associated with CVE-2018-8300 in SharePoint and similar issues in products such as .NET Reflector, Telerik JustDecompile, and JetBrains dotPeek when malicious resource files were opened or processed. The disclosures highlighted how untrusted workflow definitions and resource files could become execution vectors in enterprise environments, and Microsoft recognized the SharePoint Online findings through its bug bounty program while related technical advisories and exploit details circulated publicly.
See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
On August 30, 2018, the researcher published a retrospective stating that his 2018 SharePoint work produced two workflow-related RCE issues affecting SharePoint and on-premises deployments, resulting in CVE-2018-8284 and CVE-2018-8421 in the .NET Framework. He also noted a third SharePoint RCE involving ASP.NET .RESX deserialization, identified as CVE-2018-8300, for which no bounty was paid.
A technical report detailed remote code execution during compilation or loading of attacker-supplied XOML workflows via unsafe deserialization in the System.Workflow ecosystem. The report said SharePoint and potentially SharePoint Online could be exposed and included multiple proof-of-concept gadget chains, including one that worked against SharePoint.
On July 26, 2018, the researcher said Microsoft recognized him as a top-five bounty hunter for Q4 2018 based on two SharePoint Online remote code execution reports. He also referenced CVE-2018-8300 as another SharePoint RCE tied to .RESX resource-file deserialization.
Microsoft's July 2018 security updates fixed one of the SharePoint Online workflow-related remote code execution issues reported by the researcher, tracked as CVE-2018-8284. The flaw was described as a workflow protection bypass issue affecting SharePoint workflows.
On February 8, 2018, Soroush Dalili published technical details on code execution risks involving ASP.NET .resx and .resources files. The write-up said multiple Microsoft and third-party products were affected by unsafe resource handling and referenced related advisories and vendor fixes.
The researcher began investigating .NET deserialization issues in January 2018 after studying ysoserial.net and related attack paths such as unsafe ASP.NET ViewState/EventValidation handling. This work led to exploitation research against multiple applications, including SharePoint.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
soroush.me
Open sourcesoroush.me
Open sourcesoroush.secproject.com
Open sourcesoroush.me
Open sourcesoroush.secproject.com
Open sourcesoroush.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.