Impact
The vulnerability turns out to be an insecure deserialization flaw that allows unauthenticated remote attackers to execute arbitrary code on the server. Because the deserialization routine accepts crafted data without proper validation, an attacker can inject malicious objects that the framework will instantiate and invoke, effectively running code with the rights of the service process. This weakness directly maps to CWE‑502 and can compromise confidentiality, integrity, and availability of the host system.
Affected Systems
The affected product is DigiWin’s EasyFlow .NET. No specific version information is given in the advisory, so all releases prior to the patch issued after April 16 2026 should be considered vulnerable and must be updated.
Risk and Exploitability
The assessed CVSS score of 9.3 indicates an extremely high severity. The advisory does not provide an EPSS value, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw by sending a specially crafted serialized payload over the network, so the likely attack vector is remote. Successful exploitation would grant the attacker full control of the target machine.
OpenCVE Enrichment