PT-2025-39674 · Microsoft+1 · .Net Remoting+1

Published

1999-01-01

·

Updated

2025-09-30

·

CVE-2025-58384

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DOXENSE WATCHDOC versions prior to 6.1.1.5332
Description The software contains a flaw related to the deserialization of untrusted data. This issue, present in the .NET Remoting library within the Watchdoc administration interface, can allow for remote code execution. Approximately 157 instances are reportedly exposed. An attacker can invoke an unauthenticated API endpoint to execute arbitrary code remotely, potentially compromising the system. The vulnerability affects all printers in the network.
Recommendations Versions prior to 6.1.1.5332 should be upgraded. Restrict access to port 5744.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-12416
CVE-2025-58384
DOTNETREMOTINGCHECK

Affected Products

.Net Remoting
Doxense Watchdoc