Stats
- First seen
- March 2022
- Last seen
- October 2026
Description
Detects ysoserial deserialization payloads, which exploit unsafe .NET and Java object deserialization to run code. Spotting these indicators early helps contain an intrusion before cyberattackers expand access. The underlying flaw carries the identifier CVE-2017-11284, CVE-2016-1291, CVE-2016-3642, and 23 others.
CVEs
CVE-2016-1000031CVE-2016-1291CVE-2016-3642CVE-2017-11283CVE-2017-11284CVE-2017-12558CVE-2017-3248CVE-2017-5792CVE-2017-8962CVE-2017-8994CVE-2018-15959CVE-2018-19403CVE-2018-3191CVE-2018-3245CVE-2018-3252CVE-2018-4939CVE-2019-0192CVE-2019-12630CVE-2019-17564CVE-2019-5350CVE-2019-7091CVE-2020-10189CVE-2020-2551CVE-2020-27131CVE-2020-36239CVE-2023-20864