PT-2026-51074 · Corewcf+2 · Corewcf+1
CVE-2026-54777
·
Published
2026-06-19
·
Updated
2026-07-10
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
CoreWCF versions prior to 1.8.1
CoreWCF versions prior to 1.9.1
Description
The NetNamedPipe transport in CoreWCF allows local interception of traffic. This occurs because the transport accepts attachments to pre-existing named pipe instances. An attacker can exploit this by racing the
NamedPipeListener startup, creating the named pipe after the service publishes a unique GUID to a shared memory object but before the service creates the named pipe itself.Recommendations
Update CoreWCF to version 1.8.1.
Update CoreWCF to version 1.9.1.
Exploit
Fix
Time Of Check To Time Of Use
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Corewcf
Corewcf.Netnamedpipe