CRITICAL🇵🇱 Wersja polska

CVE-2026-58127

CVSS 9.3v4.0pub. 2026-07-01upd. 2026-07-09

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service (which runs as NT Authority\\SYSTEM and loads missing DLLs such as CRYPTBASE.DLL from the application directory) enables unauthenticated remote code execution as SYSTEM upon service restart.

🤖 AI Analysis
How it works

The PacsgearMediaServerEngine.dll library registers .NET Remoting objects under the ObjectURIs identifiers RemoteObj and UIRemoteObj, accessible via TCP on port 9000 without any authentication. An attacker can exploit the MarshalByRefObject unmarshalling technique and .NET WebClient class methods to read and write arbitrary files on the host file system. Since the ObjectURIs identifiers are identical in all default installations, the attack is repeatable on every unsecured installation. Combining the file write primitive with a DLL hijacking vulnerability — the MediaWriter service runs as NT Authority\SYSTEM and loads missing libraries (e.g., CRYPTBASE.DLL) from the application directory — enables remote code execution with SYSTEM privileges after service restart.

Impact

An unauthenticated remote attacker can read and write arbitrary files on the server, and through DLL hijacking obtain full code execution (RCE) with NT Authority\SYSTEM privileges, resulting in complete compromise of the host operating system.

Mitigation & patch

Apply patches available from the vendor according to the references. Until patches are deployed, it is recommended to block access to TCP port 9000 at the firewall level or through network segmentation, restricting access only to trusted hosts. You should also consider disabling the MediaWriter service if it is not essential.

Who is affected

PACSgear MediaWriter version 5.2.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Hyland Pacsgear

    APP
    Hyland
    ≤ 5.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2026-58126CRITICAL9.3PL ✓same product

PACSgear PACS Scan 5.2.1 — nieuwierzytelniony RCE przez .NET Remoting

CVE-2026-26339CRITICAL9.3PL ✓same vendor

RCE przez argument injection w Hyland Alfresco Transform Service

CVE-2020-25253CRITICAL9.8PL ✓same vendor

SQL Injection w Hyland OnBase — krytyczna podatność wielu wersji

CVE-2020-25251CRITICAL9.1PL ✓same vendor

Hyland OnBase — pominięcie uwierzytelnienia (Auth Bypass) po stronie klienta

CVE-2020-25254CRITICAL9.8PL ✓same vendor

SQL injection w Hyland OnBase — nieautoryzowany dostęp do bazy danych