CRITICAL🇵🇱 Wersja polska

CVE-2026-58126

CVSS 9.3v4.0pub. 2026-07-01upd. 2026-07-09

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.

🤖 AI Analysis
How it works

The vulnerability results from the exposure of a .NET Remoting TCP service on port 22222 by the PGImageExchQueue.exe process, which requires no authentication (CWE-306). An attacker can exploit this service to read and write arbitrary files on the system. Then, through DLL hijacking technique, the attacker plants a malicious DLL (e.g., CRYPTSP.DLL) in the application directory, which is loaded by the PGImageExchangeQueueSvc.exe service when the appropriate file is missing. After service restart, the malicious code is executed with NT Authority\SYSTEM privileges (CWE-502 — unsafe deserialization in .NET Remoting).

Impact

An attacker gains full arbitrary code execution on the vulnerable system with NT Authority\SYSTEM privileges, which means complete takeover of the host, including the ability to read, modify and delete data, as well as further lateral movement in the network.

Mitigation & patch

Security patches available from the vendor should be applied according to the references. Until the patch is applied, it is recommended to block access to TCP port 22222 at the firewall level and limit the system's exposure exclusively to trusted internal network segments.

Who is affected

PACSgear PACS Scan version 5.2.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Hyland Pacsgear

    APP
    Hyland
    ≤ 5.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2026-58127CRITICAL9.3PL ✓same product

PACSgear MediaWriter — nieuwierzytelniony RCE przez .NET Remoting TCP

CVE-2026-26339CRITICAL9.3PL ✓same vendor

RCE przez argument injection w Hyland Alfresco Transform Service

CVE-2020-25253CRITICAL9.8PL ✓same vendor

SQL Injection w Hyland OnBase — krytyczna podatność wielu wersji

CVE-2020-25251CRITICAL9.1PL ✓same vendor

Hyland OnBase — pominięcie uwierzytelnienia (Auth Bypass) po stronie klienta

CVE-2020-25254CRITICAL9.8PL ✓same vendor

SQL injection w Hyland OnBase — nieautoryzowany dostęp do bazy danych