News

CVE-2025-23120 and the earlier CVE-2024-40711 (9.8) are both uncontrolled deserialization vulnerabilities on BinaryFormatter – a buggy, deprecated component Microsoft says cannot be trusted to ...