CVE-2019-10068 is an unsafe deserialization vulnerability in the Kentico CMS staging service affecting Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and Kentico 9.x. Insufficient validation of security headers allows a specially crafted request to bypass the staging service's initial authentication controls and reach deserialization of attacker-controlled .NET object data. An attacker can abuse the deserialization behavior to execute code on the server hosting the Kentico instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single operational Python PoC exploit (cve-2019-10068-poc.py) plus a README. The exploit targets Kentico CMS CVE-2019-10068, a pre-auth .NET deserialization RCE reachable via the SOAP web service endpoint /CMSPages/Staging/SyncServer.asmx (ProcessSynchronizationTaskData). The script generates a SoapFormatter payload using a bundled Ruby helper that imports Metasploit Framework’s .NET deserialization utilities (Msf::Util::DotNetDeserialization) and uses the WindowsIdentity gadget chain. The resulting command executed on the target uses PowerShell to write a base64-encoded ASPX web shell (x.aspx) into one of several hardcoded candidate IIS/Azure web root directories. After sending the SOAP request, it checks for expected exception strings indicating gadget execution and then verifies shell availability by requesting /x.aspx?c=whoami. TLS certificate validation is explicitly disabled. Overall purpose: achieve unauthenticated RCE and persistent command execution via a dropped ASPX web shell, with basic automation for trying multiple web root paths.
This repository contains a single Metasploit module targeting a remote code execution vulnerability (CVE-2019-10068) in Kentico CMS (versions 12.0.14 and earlier) on Windows. The exploit leverages an insecure .NET deserialization issue in the SyncServer.asmx SOAP web service, specifically the ProcessSynchronizationTaskData method, which accepts attacker-controlled XML input in the stagingTaskData parameter. The module allows unauthenticated attackers to execute arbitrary commands or payloads (EXE, command, or PowerShell) on the target server. The main endpoints involved are /CMSPages/Staging/SyncServer.asmx and its /ProcessSynchronizationTaskData method. The exploit is fully weaponized, supporting multiple payload types and architectures, and is part of the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An N-day vulnerability in Kentico CMS reportedly exploited by QTFY for initial access.
A Kentico CMS vulnerability exploited by QTFY at a U.S. telecommunications company.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.