External risk intelligence

Newforma Info Exchange Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-35050

Newforma Info Exchange (NIX) is designed specifically to facilitate external collaboration and data exchange between internal project teams and external partners. By its nature, the service is intended to be reachable over the internet, and the vulnerable endpoint is a component of this public-facing web interface.

Missing Authentication

Newforma Project Center

2024.3

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Newforma Info Exchange allows remote attackers to execute code on affected systems with elevated privileges. This issue impacts Newforma Project Center Server, which relies on the vulnerable Info Exchange component for its operations, potentially exposing associated project data.

  • Remote code execution in Newforma systems.
  • Critical flaw impacts external collaboration platform.
  • Assess relevance and exposure for project data.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach a vulnerable endpoint on Newforma Info Exchange (NIX) to send specially crafted data. This data can be processed by the Newforma Project Center Server (NPCS), potentially allowing the attacker to execute arbitrary code with network service privileges on the NPCS system.

  • Attacker can reach an internet-facing service.
  • Sending malicious serialized .NET data triggers vulnerability.
  • Attacker can gain privileged code execution.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could execute arbitrary code on systems running Newforma Info Exchange when interacting with the '/remoteweb/remote.rem' endpoint. This could allow an attacker to compromise an associated Newforma Project Center Server.

  • System code execution is at risk.
  • Attackers send malicious .NET data.
  • Compromised servers could result.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Newforma Project Center Server (NPCS) team, likely in coordination with platform or infrastructure teams, is responsible for securing the Newforma Info Exchange (NIX) environment. The first step is to identify all NIX instances, determine their network reachability, confirm their criticality, and locate the accountable owner for remediation planning.

  • Identify affected systems and owners.
  • Verify external reachability of the endpoint.
  • Plan and coordinate remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Newforma Info Exchange?

Newforma Info Exchange is a collaboration platform used by project teams to securely share documents and data with external partners. It integrates closely with the Newforma Project Center Server to manage project information. Because it serves as a gateway for external communication, it acts as a central hub for file transfers and project coordination, often sitting between internal company networks and the public internet.

What does this vulnerability mean for Newforma Info Exchange?

This is a critical security weakness involving deserialization and missing authentication. In technical terms, the application incorrectly handles untrusted .NET data sent to a specific web endpoint. Because the software does not verify the origin or content of this data, an attacker can trick the system into running malicious commands, effectively taking control of the server with elevated system privileges.

How is this vulnerability triggered?

An attacker triggers this by sending specially crafted, serialized .NET data to the '/remoteweb/remote.rem' endpoint. The flaw is triggered specifically when the application processes this data without proper checks. Merely visiting the website or using the platform's standard project features does not trigger the bug; it requires the deliberate submission of this malicious, structured data to that specific backend endpoint.

Is my system at risk according to Halo Surface Signal?

The risk is very high if your instance is reachable over the internet. Halo Surface Signal identifies Newforma Info Exchange as a platform explicitly designed to facilitate external data exchange, meaning these endpoints are frequently public-facing by design. If your deployment is exposed to the internet to support this collaboration, it is a primary candidate for external access attempts.

What are the first steps to secure my environment?

Begin by identifying all instances of the Info Exchange server and confirming their network reachability. Coordinate with your infrastructure or platform team to restrict access to the '/remoteweb/remote.rem' endpoint. Using tools like the IIS URL Rewrite Module to block traffic to this specific path is an effective way to prevent unauthorized access while you plan for further security updates.

References