Impact
Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that permits low‑privileged local users to elevate to SYSTEM. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe. The listener is configured with BinaryServerFormatterSinkProvider and TypeFilterLevel set to Full, allowing a low‑privileged local attacker to send YSoSerial.NET-generated BinaryFormatter payloads that trigger arbitrary code execution as the SYSTEM account. This flaw maps to CWE‑502 – insecure deserialization, and leads to a full compromise of the host including data modification, exfiltration, and persistence installation.
Affected Systems
Seagull Software, LLC’s BarTender 2021 product, versions R1 through 12.0.1 inclusive, is affected. The vulnerable component is BtSystem.Service.exe, which hosts a .NET Remoting listener on TCP port 7375 bound to localhost.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the EPSS score of 0.0013 (<1%) indicates a low overall likelihood of exploitation. However, the local‑only attack surface means that an attacker with low‑privileged local access could realistically gain SYSTEM privileges. This vulnerability is not listed in CISA’s KEV catalog, and attainment of SYSTEM privileges would constitute a catastrophic security breach.
OpenCVE Enrichment