Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
How could an attacker exploit this vulnerability? An attacker could supply a maliciously crafted continuation token that, when processed by the Azure AI Language Conversations Authoring SDK, triggers unsafe deserialization and executes attacker‑controlled code on the system using the SDK.
<a href="https://www.linkedin.com/in/muhammad-fadilullah-dzaki-a9080a2b5/">Muhammad Fadilullah Dzaki</a>