Insecure Deserialization Vulnerability in Veritas InfoScale by Arctera
CVE-2025-27816
9.8CRITICAL
What is CVE-2025-27816?
A security vulnerability has been identified in Veritas InfoScale versions 7.0 through 8.0.2, where the .NET remoting endpoint is susceptible to exploitation due to the insecure deserialization of potentially untrusted messages. This weakness exists in the Windows Plugin_Host service, active on all servers hosting InfoScale. This service operates when applications are configured for Disaster Recovery (DR) using the DR wizard. To mitigate this risk, it is advisable to disable the Plugin_Host service manually.