From the MSFT documentation on BinaryFormatter:
"As a simpler analogy, assume that calling BinaryFormatter.Deserialize over a payload is the equivalent of interpreting that payload as a standalone executable and launching it."
Can it run Doom though?
12 months ago