PowerFolder Server commons-collections Java Library Deserialization Vulnerability Remote Code Execution Exploit

PowerFolder Server is prone to a remote vulnerability that allows attackers to take advantage of a deserialization vulnerability present in the commons-collections java library. By exploiting known methods, it is possible to remotely load a java class and inject custom Java bytecode. The exploit abuses this to download and execute an executable with Impact's agent.
Exploit Platform
Exploit Type
Product Name