[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Tue, 18 Aug 2026 06:04:30 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Cinegy
Cinegize 2026-02-05 installer (Cinegy GmbH). The research is published and a
proof-of-concept is available.
Pre-authentication RCE (BinaryFormatter deserialization) (CVSS 9.8,
pre-authentication)
Cinegy Cinegize (2026-02-05 installer) registers a Windows service listening on
TCP 51140 with a DotNetty pipeline that deserializes .NET BinaryFormatter
objects before the authorization handler runs. An unauthenticated remote
attacker sends a TypeConfuseDelegate gadget frame; deserialization triggers
Process.Start as LocalSystem. No authentication, no license gate, and a default
inbound firewall rule make the service reachable in a default install.
Dynamically verified.
Impact: Full compromise of the broadcast and media-workflow automation host as
LocalSystem. The attacker can disrupt broadcast operations, execute arbitrary
commands, and access media assets.
Advisory:
https://0day-rubbish.com/blog/cinegy-cinegize-unauth-binaryformatter-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
Vendor has been notified. CVE ID is pending.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/