A critical remote code execution vulnerability has been discovered in CyberArk Password Vault application. The vulnerability affects one of such Enterprise Password Vault apps designed by CyberArk. The flaw is due to the way web server unsafely handle deserialization operations, which could allow attackers to execute code on the server processing the deserialized data. CyberArk has released a full proof-of-concept code to demonstrate the vulnerability using ysoserial.net, an open source tool for generating payloads for.NET applications.
Source: https://thehackernews.com/2018/04/enterprise-password-vault.html