Insecure Deserialization Vulnerability in Veritas InfoScale by Arctera
CVE-2025-27816
9.8CRITICAL
Summary
A security vulnerability has been identified in Veritas InfoScale versions 7.0 through 8.0.2, where the .NET remoting endpoint is susceptible to exploitation due to the insecure deserialization of potentially untrusted messages. This weakness exists in the Windows Plugin_Host service, active on all servers hosting InfoScale. This service operates when applications are configured for Disaster Recovery (DR) using the DR wizard. To mitigate this risk, it is advisable to disable the Plugin_Host service manually.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved