Arbitrary Code Execution in Stimulsoft Reports 2013.1.1600.0

Arbitrary Code Execution in Stimulsoft Reports 2013.1.1600.0

CVE-2021-42777 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start.

Learn more about our Cis Benchmark Audit For Server Software.