.NET Remoting, a deprecated remote invocation technology still embedded in some enterprise software, remains vulnerable to serious exploitation paths that can lead to remote code execution, arbitrary file read/write, and broader host compromise. Research from CODE WHITE and James Forshaw shows that insecure use of BinaryFormatter and SoapFormatter, weak protections across HTTP, TCP, and IPC remoting channels, and unsafe handling of MarshalByRefObject and ObjRef data can let attackers trigger deserialization abuse and even force outbound remoting connections. The reports warn that these weaknesses are architectural rather than isolated implementation bugs, leaving legacy deployments exposed even on supported .NET Framework versions.
Forshaw's earlier work also demonstrated a Low Type Filter bypass that can still work against fully updated .NET Framework 4.8 remoting services, enabling attackers who know the server URI and can meet any authentication requirements to access files and potentially bootstrap command execution. Public proof-of-concept tooling, including ExploitRemotingService and newer offensive additions such as an ObjRef gadget and a rogue remoting server, now supports exploitation over TCP and Windows IPC named pipes with functions such as command execution, file upload/download, directory listing, and assembly execution. The combined findings reinforce that organizations should treat exposed or internally reachable .NET Remoting services as high risk and migrate away from the technology.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
The GitHub repository documentation described ExploitRemotingService capabilities across TCP and IPC remoting, including command execution, file transfer, directory listing, assembly execution, and lease-based low-type-filter bypass. It also noted that the repository includes a deliberately vulnerable test service with the security fix disabled for validation.
CODE WHITE published research revisiting .NET Remoting security, detailing architectural weaknesses that can lead to remote code execution and describing new offensive additions. The post introduced enhancements to ExploitRemotingService, including options such as --useobjref, --remname, and --ipcserver, plus a new ObjRef gadget for YSoSerial.Net and a RogueRemotingServer.
James Forshaw described a new exploitation technique that bypasses .NET Remoting Low Type Filter protections using remoting lifetime services and callback/coercion behavior. The write-up said the technique was unpatched, worked against fully updated .NET Framework installations such as .NET 4.8, and was implemented as the "uselease" option.
James Forshaw published technical analysis of CVE-2014-1806 and CVE-2014-4149 in .NET Remoting, describing how Microsoft's initial fix could be bypassed and how TypeFilterLevel.Full services remained exposed. He also identified Intel Rapid Storage Technology 11.0.0.1032 as shipping a vulnerable local .NET Remoting service in IAStorDataMgrSvc.exe that could be exploited for SYSTEM-level privilege escalation.
The ExploitRemotingService proof-of-concept tool for attacking vulnerable .NET Remoting services was created by James Forshaw. The tool targets services affected by CVE-2014-1806 or CVE-2014-4149.
James Forshaw authored the white paper "Are you my Type? Breaking .NET Through Serialization," detailing how unsafe .NET deserialization and .NET Remoting could enable remote code execution, privilege escalation, information disclosure, and sandbox escapes. The paper also described a Low TypeFilterLevel bypass using System.Data.DataSet and discussed vulnerabilities later addressed in MS12-035, including CVE-2012-0160 and CVE-2012-0161.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
docs.microsoft.com
Open sourcedocs.microsoft.com
Open sourcegithub.com
Open sourcecode-white.com
Open sourcetiraniddo.dev
Open sourcetiraniddo.dev
Open sourcemedia.blackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.