PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service (which runs as NT Authority\\SYSTEM and loads missing DLLs such as CRYPTBASE.DLL from the application directory) enables unauthenticated remote code execution as SYSTEM upon service restart.
The PacsgearMediaServerEngine.dll library registers .NET Remoting objects under the ObjectURIs identifiers RemoteObj and UIRemoteObj, accessible via TCP on port 9000 without any authentication. An attacker can exploit the MarshalByRefObject unmarshalling technique and .NET WebClient class methods to read and write arbitrary files on the host file system. Since the ObjectURIs identifiers are identical in all default installations, the attack is repeatable on every unsecured installation. Combining the file write primitive with a DLL hijacking vulnerability — the MediaWriter service runs as NT Authority\SYSTEM and loads missing libraries (e.g., CRYPTBASE.DLL) from the application directory — enables remote code execution with SYSTEM privileges after service restart.
An unauthenticated remote attacker can read and write arbitrary files on the server, and through DLL hijacking obtain full code execution (RCE) with NT Authority\SYSTEM privileges, resulting in complete compromise of the host operating system.
Apply patches available from the vendor according to the references. Until patches are deployed, it is recommended to block access to TCP port 9000 at the firewall level or through network segmentation, restricting access only to trusted hosts. You should also consider disabling the MediaWriter service if it is not essential.
PACSgear MediaWriter version 5.2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHyland Pacsgear
APPHyland≤ 5.2.1
Related vulnerabilities
PACSgear PACS Scan 5.2.1 — nieuwierzytelniony RCE przez .NET Remoting
RCE przez argument injection w Hyland Alfresco Transform Service
SQL Injection w Hyland OnBase — krytyczna podatność wielu wersji
Hyland OnBase — pominięcie uwierzytelnienia (Auth Bypass) po stronie klienta
SQL injection w Hyland OnBase — nieautoryzowany dostęp do bazy danych