CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard
A web application accepts a serialized object from a client-side cookie and reconstructs it into an executable object on the server without validation. An attacker modifies the serialized data to include malicious object properties, resulting in remote code execution on the server. Which vulnerability class does this best represent?
- ATOCTOU race condition
- BReflected cross-site scripting
- CInteger overflow
- DInsecure deserialization
Show answer & explanationAnswer & explanation
Correct answer: D. Insecure deserialization
Insecure deserialization occurs when an application reconstructs objects from untrusted serialized data without proper validation, allowing an attacker to craft malicious serialized payloads that execute arbitrary code or alter application logic when deserialized on the server.
Why the other options are wrong
- A. TOCTOU exploits a timing gap between check and use, unrelated to deserializing crafted objects.
- B. Reflected XSS executes script in a victim's browser via a crafted link, not server-side object reconstruction.
- C. Integer overflow involves numeric value wraparound, not object serialization.
Insecure Deserialization
A vulnerability where an application deserializes untrusted data without validation, allowing attackers to manipulate serialized objects to execute code or alter logic.
- Common in Java, PHP, and .NET applications using object serialization
- Can lead to remote code execution, denial of service, or privilege escalation
- Mitigated by avoiding native serialization for untrusted data and using integrity checks
Memory trick: Deserialization: unwrapping a gift box that's rigged to explode.