ASNA Products Deserialization Vulnerability in .NET Remoting Allowing Privilege Escalation and Code Execution

Vulnerability

A deserialization vulnerability has been identified in ASNA Assist and ASNA Registrar versions prior to 2025-03-31. This issue affects several ASNA products, including DataGate for SQL Server, DataGate Component Suite, DataGate Monitor, DataGate WebPak, Monarch for .NET, Encore RPG, Visual RPG .NET Framework, WingsRPG, Mobile RPG, Monarch Framework for .NET Framework, Browser Terminal, Visual RPG Classic, Visual RPG Deployment, and DataGate Studio. All these products are vulnerable to deserialization attacks via .NET remoting, a technology that can be exploited using well-known deserialization techniques. The vulnerability is particularly concerning because the affected services run with SYSTEM-level rights, allowing for exploitation that could lead to unauthorized privilege escalation and arbitrary code execution.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation and arbitrary code execution, given that the affected services operate with SYSTEM-level rights.

Remediation

Users are advised to update to ASNA products version 2025-03-31 or later. For more information, visit the ASNA security update page.

Added: Jul 3, 2025, 2:27 PM
Updated: Jul 3, 2025, 3:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.