An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unrestricted DLL Loading in Biztalk360 | |
| Weaknesses | CWE-285 CWE-94 |
Thu, 09 Apr 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kovai
Kovai biztalk360 |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kovai
Kovai biztalk360 |
|
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Biztalk360
Biztalk360 biztalk360 |
|
| Vendors & Products |
Biztalk360
Biztalk360 biztalk360 |
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unrestricted DLL Loading in Biztalk360 | |
| Weaknesses | CWE-285 CWE-94 |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T14:39:54.309Z
Reserved: 2025-09-19T00:00:00.000Z
Link: CVE-2025-59710
No data.
Status : Analyzed
Published: 2026-04-03T15:16:04.500
Modified: 2026-04-09T00:46:56.803
Link: CVE-2025-59710
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:29:21Z