macc /
EN FR
Book a meeting
← Back to console
Critical CCB · Belgium CVE-2025-54539

Critical Deserialization of Untrusted Data vulnerability in Apache Ac…

Published

Description

CVE-2025-54539 is a deserialization vulnerability in the Apache ActiveMQ NMS AMQP Client used by .NET applications when connecting to AMQP servers. The client performs binary deserialization of data received from an AMQP broker without sufficient validation or sandboxing. Maliciously crafted serialized objects returned by a broker or injected via a man-in-the-middle can trigger object instantiation and execution of code paths during deserialization. The practical result is remote code execution (RCE) in the context of the client process. The defect affects all NMS AMQP releases up to and including 2.3.0 and is fixed in 2.4.0.