PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.
The vulnerability results from the exposure of a .NET Remoting TCP service on port 22222 by the PGImageExchQueue.exe process, which requires no authentication (CWE-306). An attacker can exploit this service to read and write arbitrary files on the system. Then, through DLL hijacking technique, the attacker plants a malicious DLL (e.g., CRYPTSP.DLL) in the application directory, which is loaded by the PGImageExchangeQueueSvc.exe service when the appropriate file is missing. After service restart, the malicious code is executed with NT Authority\SYSTEM privileges (CWE-502 — unsafe deserialization in .NET Remoting).
An attacker gains full arbitrary code execution on the vulnerable system with NT Authority\SYSTEM privileges, which means complete takeover of the host, including the ability to read, modify and delete data, as well as further lateral movement in the network.
Security patches available from the vendor should be applied according to the references. Until the patch is applied, it is recommended to block access to TCP port 22222 at the firewall level and limit the system's exposure exclusively to trusted internal network segments.
PACSgear PACS Scan version 5.2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHyland Pacsgear
APPHyland≤ 5.2.1
Related vulnerabilities
PACSgear MediaWriter — nieuwierzytelniony RCE przez .NET Remoting TCP
RCE przez argument injection w Hyland Alfresco Transform Service
SQL Injection w Hyland OnBase — krytyczna podatność wielu wersji
Hyland OnBase — pominięcie uwierzytelnienia (Auth Bypass) po stronie klienta
SQL injection w Hyland OnBase — nieautoryzowany dostęp do bazy danych