CVE-2023-32571 is a critical vulnerability in System.Linq.Dynamic.Core (versions 1.0.7.10 through 1.2.25) that allows attackers to execute arbitrary code and commands by passing crafted, untrusted input to methods such as Where, Select, and OrderBy. The vulnerability arises from a 2016 code change that permitted public methods returning accessible types to be called, enabling abuse of the Invoke method for arbitrary method execution. This flaw is particularly dangerous because Dynamic Linq is widely used in major .NET frameworks and applications, and the vulnerable methods are often exposed to user input, sometimes pre-authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept exploit for CVE-2023-32571, a remote code execution vulnerability in System.Linq.Dynamic.Core (versions 1.0.7.10 to 1.2.25). The repository is structured as a Visual Studio solution with two main projects: 'Generator' and 'Payload'. - The 'Generator' project (Generator/Program.cs) is a command-line tool that builds payloads for exploiting the vulnerability. It supports two modes: 1. AssemblyLoad: Loads and executes a custom .NET assembly (DLL) on the target. The user supplies the DLL, type name, and parameters (commonly a DNS or HTTP endpoint for OOB verification). 2. ProcessStart: Executes arbitrary system commands on the target (e.g., ping, whoami). - The 'Payload' project (Payload/Payload.cs) is a minimal .NET class that, when instantiated, triggers a DNS lookup to a user-supplied domain (e.g., a Burp Collaborator or Interactsh endpoint), allowing the attacker to verify code execution via out-of-band callbacks. The exploit does not target a specific network endpoint but is designed to be used against any application using a vulnerable version of System.Linq.Dynamic.Core that parses untrusted input. The payloads can be customized to trigger DNS or HTTP callbacks for verification. The repository includes a detailed README with build and usage instructions, and references to official advisories. No hardcoded IPs, URLs, or domains are present in the code; the attacker supplies these at runtime. The exploit is a functional proof-of-concept and does not include weaponized automation or post-exploitation features.
This repository provides a working proof-of-concept (POC) for exploiting CVE-2023-32571, a remote code execution vulnerability in System.Linq.Dynamic.Core (version 1.2.25). The exploit leverages a dynamic LINQ injection in an ASP.NET Core web application. The vulnerable endpoint is '/api/products' (POST), which takes a JSON body with a 'name' parameter. This parameter is unsafely interpolated into a dynamic LINQ query, allowing attackers to inject arbitrary C# code. The README details payloads that use reflection and .NET internals to invoke 'System.Diagnostics.Process.Start', enabling arbitrary command execution on both Windows and Linux targets. The repository includes Docker and docker-compose files to easily set up a vulnerable lab environment, exposing the application on http://localhost:8000/. The exploit is operational, providing real RCE, and is not just a detection script. The main code files are in the 'DynamicLinqToRce' directory, with the vulnerability implemented in 'Controllers/ProductsController.cs'.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.