ZeroHour

CVE-2025-71260

PoC moderate

Authenticated ASP.NET VIEWSTATE Deserialization RCE in BMC FootPrints ITSM

CVSS 4.0
8.7 high
EPSS
34%p98
Published
()
Modified
AI analysis

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data flaw (CWE-502) in the ASP.NET servlet's handling of the VIEWSTATE parameter. An authenticated attacker with low privileges can submit crafted serialized objects in the VIEWSTATE parameter over the network, with no user interaction required. Successful exploitation yields arbitrary code execution, allowing the attacker to fully compromise the ITSM application and its host (high impact to confidentiality, integrity, and availability). Organizations running any affected FootPrints ITSM release are exposed, particularly where the web interface is reachable from untrusted networks. No confirmed in-the-wild exploitation has been reported and it is not in CISA KEV, but a public PoC exists (WatchTowr Labs research, which also describes pre-authentication RCE chains against FootPrints), and the 34.4% EPSS score (98th percentile) indicates an elevated probability of exploitation within 30 days.

What to do: Upgrade each deployment to the remediation hotfix matching its baseline release, choosing from the vendor-listed builds (20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01). Until patched, restrict network access to the FootPrints web interface, verify ASP.NET VIEWSTATE integrity (MAC/encryption) settings are enabled, and review web logs for suspicious POST requests to the ASP.NET servlet.

Affected
bmc FootPrints ITSM20.20.02 through 20.24.01.001
Estimated exposure
moderateon the order of 1,000-10,000 installations (estimated) — FootPrints ITSM is a legacy on-prem enterprise ITSM product typically deployed as one instance per organization; the data contains no install-base or internet-exposure scan counts, so this order-of-magnitude estimate is based on deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Vendors
bmc
Products
footprints
Weakness
CWE-502
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news