Impact
Seagull Software BarTender 2010, 2016, and 2019 expose an unauthenticated .NET Remoting endpoint on TCP port 7375 that uses BinaryServerFormatterSinkProvider with TypeFilterLevel set to Full. The flaw allows an attacker to craft serialized objects that are unmarshalled by BtSystem.Service.exe, leading to arbitrary file read/write via the .NET WebClient class, or to coerce NTLMv2 authentication by supplying a UNC path to an attacker‑controlled server. This can result in sensitive credential disclosure, remote code execution, or lateral movement depending on the privileges of the service account. The service runs under NT AUTHORITY\\SYSTEM, thus a successful exploit would give the attacker full control of the host.
Affected Systems
Affected vendors include Seagull Software, LLC and products are BarTender 2010, BarTender 2016, and BarTender 2019. No other product versions are listed as affected.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is classified as critical. The EPSS score of < 1% indicates a very low probability of exploitation, but the attack vector remains network‑based; an unauthenticated attacker can trigger the flaw from any host that can reach TCP port 7375. Because the service runs as SYSTEM, successful exploitation would grant full control over the host, making this a high‑risk vulnerability in any environment where the service is exposed. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment