Impact
Seagull Software BarTender 2010, 2016, and 2019 expose an unauthenticated .NET Remoting endpoint on TCP port 7375 that accepts serialized objects with BinaryServerFormatterSinkProvider and a TypeFilterLevel set to Full. An attacker can craft a malicious payload that is unmarshalled by BtSystem.Service.exe, allowing arbitrary file read and write, or coerce NTLMv2 authentication by providing a UNC path to a malicious server. Because the service runs under NT AUTHORITY\SYSTEM, a successful exploitation grants the attacker full control of the host, enabling remote code execution, credential disclosure, or lateral movement. The vulnerability is a critical authentication bypass (CWE‑306) combined with insecure deserialization (CWE‑502).
Affected Systems
Affected vendors include Seagull Software, LLC and the products are BarTender 2010, BarTender 2016, and BarTender 2019. Versions of BarTender 2016 up to release 9 and BarTender 2019 up to release 10 are vulnerable; earlier releases of the three products are also impacted.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is classified as critical. The EPSS score of less than 1% indicates a very low current probability of exploitation, yet the attack vector is network-based; any host that can reach TCP port 7375 could trigger the flaw. Since the service runs with SYSTEM privileges, compromise of the endpoint would yield full administrative control. The vulnerability is not listed in the CISA KEV catalog, but its severity and potential impact warrant immediate remediation.
OpenCVE Enrichment