CVE-2025-27816: Critical severity Arctera InfoScale vulnerability
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The vulnerability is present in the Windows PluginHost service, which runs on all the servers where InfoScale is installed. The service is used only when applications are configured for Disaster Recovery (DR) using the DR wizard. Disabling the PluginHost service manually will eliminate the vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Manually disable the Windows Plugin_Host service on servers where InfoScale is installed to eliminate the vulnerability (vulnerable in Arctera InfoScale 7.0 through 8.0.2).
Arctera InfoScale Plugin_Host service (Windows) Plugin_Host service state = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27816?
The severity of CVE-2025-27816 is classified as high due to the potential for remote exploitation.
How do I fix CVE-2025-27816?
To fix CVE-2025-27816, upgrade your Arctera InfoScale software to version 8.0.3 or later.
What systems are affected by CVE-2025-27816?
CVE-2025-27816 affects Arctera InfoScale versions 7.0 through 8.0.2.
What type of vulnerability is CVE-2025-27816?
CVE-2025-27816 is an insecure deserialization vulnerability that can be exploited through a .NET remoting endpoint.
What can an attacker do with CVE-2025-27816?
An attacker can exploit CVE-2025-27816 to execute arbitrary code on affected systems via crafted messages.