Microsoft:
The BinaryFormatter type is dangerous and is not recommended for data processing... BinaryFormatter is insecure and can't be made secure.
Citrix:
We have the facts and we're voting Yes for using BinaryFormatter for processing data in our product.
CVE(s) TBD...