Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
| Vendor | Product | Versions |
|---|---|---|
| digital knowledge | knowledgedeliver | 0 |
Updated description with detailed technical information about the exploitation and added new IoCs and tags related to Godzilla and Cobalt Strike.
Updated description with significant technical details, added vendor and product information, marked exploit as available, and included new IoCs and MITRE ATT&CK technique.
Updated description with new technical details, changed severity to HIGH, and added CVSS estimate of 7.5.
Initial creation