CVE-2018-14878: High severity jetbrains dotpeek vulnerability
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14878?
CVE-2018-14878 has a severity rating that indicates it poses a significant risk of code execution by attackers.
How do I fix CVE-2018-14878?
To mitigate CVE-2018-14878, update JetBrains dotPeek to version 2018.2 or later, and JetBrains ReSharper Ultimate to version 2018.1.4 or later.
What software is affected by CVE-2018-14878?
CVE-2018-14878 affects JetBrains dotPeek before version 2018.2 and JetBrains ReSharper Ultimate before version 2018.1.4.
What kind of attack does CVE-2018-14878 enable?
CVE-2018-14878 allows attackers to execute arbitrary code through the deserialization of untrusted data in decompiled .NET objects.
When was CVE-2018-14878 disclosed?
CVE-2018-14878 was disclosed in August 2018.