According to watchTowr's findings, attackers trigger the pre-auth deserialization bug to achieve remote code execution (RCE) ...