[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)



0day Rubbish Research Team is publicly disclosing a vulnerability in Cinegy 
Cinegize 2026-02-05 installer (Cinegy GmbH). The research is published and a 
proof-of-concept is available.

Pre-authentication RCE (BinaryFormatter deserialization) (CVSS 9.8, 
pre-authentication)

Cinegy Cinegize (2026-02-05 installer) registers a Windows service listening on 
TCP 51140 with a DotNetty pipeline that deserializes .NET BinaryFormatter 
objects before the authorization handler runs. An unauthenticated remote 
attacker sends a TypeConfuseDelegate gadget frame; deserialization triggers 
Process.Start as LocalSystem. No authentication, no license gate, and a default 
inbound firewall rule make the service reachable in a default install. 
Dynamically verified.

Impact: Full compromise of the broadcast and media-workflow automation host as 
LocalSystem. The attacker can disrupt broadcast operations, execute arbitrary 
commands, and access media assets.

Advisory: 
https://0day-rubbish.com/blog/cinegy-cinegize-unauth-binaryformatter-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/