Product
An unauthenticated or low-privilege attacker can achieve remote code execution in Microsoft Web Deploy versions prior to 10.0.2001 by exploiting insecure deserialization of the 'MSDeploy.SyncOptions' HTTP header.