Executive brief
Seagull Scientific BarTender is a professional software suite used by businesses to design and print labels, barcodes, and RFID tags. A security flaw in certain versions allows a user with limited access to the computer to gain full administrative control (SYSTEM privileges). This could allow an unauthorized person to bypass security restrictions, access sensitive data, or disrupt labeling operations on the affected machine.
Technical details
The vulnerability exists within the DataServiceSingleton .NET Remoting endpoint, which is managed by the BtSystem.Service.exe process. While the service is bound to localhost on TCP port 7375, it is configured with the insecure BinaryServerFormatterSinkProvider and a TypeFilterLevel set to 'Full'. A local attacker with low privileges can exploit this by sending a malicious serialized payload (e.g., generated via YSoSerial.NET) to the endpoint. Successful exploitation results in arbitrary code execution with SYSTEM-level privileges. This specific CVE focuses on the local privilege escalation vector in newer versions where the service is restricted to the loopback interface.
Affected products
- Seagull Scientific BarTender 2021 R1 through 12.0.1
Timeline
- 2026-06-03: disclosed: Initial researcher disclosure by GM Sectec researchers.
- 2026-06-04: advisory: NVD and VulnCheck published advisory details.