External risk intelligence

Newforma Project Center Server Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2025-35051

The vulnerability resides in Newforma Project Center Server on a specific TCP port (9003). While network-reachable, the recommended deployment architecture for this product is within an internal network, and it is not typically designed to be exposed directly to the public internet.

Missing Authentication

Newforma Project Center

2024.3

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in Newforma Project Center Server that could allow an unauthenticated attacker to execute arbitrary code. While the affected endpoint is intended for internal network use, its presence warrants confirmation of its accessibility.

  • Code execution flaw in Project Center Server.
  • Internal network systems may be at risk.
  • Confirm relevance and exposure internally.

Attack Path

How an attacker could exploit the issue

An attacker could target the Newforma Project Center Server by sending serialized .NET data to its '/ProjectCenter.rem' endpoint. This endpoint is exposed on TCP port 9003, and according to the product's typical architecture, it is accessible from within an internal network. If successful, this could allow the attacker to execute arbitrary code on the server with the privileges of 'NT AUTHORITY\\NetworkService'.

  • Requires internal network access.
  • Vulnerable endpoint accepts serialized data.
  • Leads to arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When Newforma Project Center Server is accessible on an internal network, an unauthenticated attacker could potentially execute arbitrary code. This could impact the confidentiality, integrity, and availability of the affected system.

  • System data and service behavior are at risk.
  • Exposure can occur via the Project Center Server endpoint.
  • Arbitrary code execution could occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Newforma Project Center Server, when exposed via the `/ProjectCenter.rem` endpoint, presents a critical risk of arbitrary code execution. Given that the recommended architecture places this endpoint on an internal network, the primary responsibility likely falls to the Infrastructure and Security Teams to ensure network segmentation and access controls are strictly enforced. The initial practical step involves identifying all instances of the Project Center Server, confirming their network reachability, and assessing their business criticality to prioritize remediation efforts.

  • Own the issue: Infrastructure and Security Teams.
  • Verify first: Network accessibility and business criticality.
  • Action: Restrict network access to the endpoint.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Newforma Project Center Server?

Newforma Project Center Server is an enterprise software platform used by architecture, engineering, and construction firms to manage project information, document workflows, and facilitate team collaboration. It serves as a central hub for handling large volumes of project-related files and data, often integrating with email systems and file repositories to keep project teams synchronized across complex organizational structures.

Why is CVE-2025-35051 considered a deserialization vulnerability?

This CVE involves the insecure handling of serialized .NET data, which falls under the weakness class of Deserialization of Untrusted Data (CWE-502). When the server automatically processes this incoming data without proper verification, it can inadvertently interpret malicious input as executable commands, leading to unauthorized remote code execution on the underlying system.

How is this vulnerability triggered?

An attacker triggers this flaw by sending specially crafted, serialized .NET data to the '/ProjectCenter.rem' endpoint on port 9003/tcp. The vulnerability is not triggered by standard, legitimate user operations within the application. It requires the attacker to have network reachability to this specific service port to successfully deliver the malicious payload.

Is my instance reachable based on Halo Surface Signal?

Halo Surface Signal notes that while the vulnerability is network-reachable on port 9003, it is classified as 'Unlikely' to be internet-facing. Because Newforma Project Center Server is designed to operate within internal network boundaries, your primary concern is whether this service has been inadvertently exposed to broader, less trusted segments of your internal or external network infrastructure.

What are the first steps to secure my environment?

Begin by auditing your infrastructure to locate all active Newforma Project Center Server instances. Once identified, verify their current network accessibility. The most effective immediate step is to implement network segmentation or access control lists that restrict traffic to port 9003, ensuring the service is only reachable by authorized systems and users within your private, trusted network.

References