CVE-2026-58127: PACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service

Published Jul 1, 2026
·
Updated

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service (which runs as NT Authority\\SYSTEM and loads missing DLLs such as CRYPTBASE.DLL from the application directory) enables unauthenticated remote code execution as SYSTEM upon service restart.

Affected Software

2 affected components
PACSgear MediaWriter=5.2.1
Hyland Pacsgear<=5.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PACSgear MediaWriter to a version that resolves this vulnerability.

    Fixed in 5.2.1
  2. Compensating control

    Immediately restrict network access to PACSgear MediaWriter’s .NET Remoting TCP service on port 9000 (PacsgearMediaServerEngine.dll) to trusted IPs only, since it is exposed without any authentication requirement.

Event History

Jul 1, 2026
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-58127?

CVE-2026-58127 has a critical severity score of 9.3.

2

How do I fix CVE-2026-58127?

To mitigate CVE-2026-58127, ensure proper authentication mechanisms are implemented for the .NET Remoting TCP service.

3

What are the potential impacts of CVE-2026-58127?

Exploiting CVE-2026-58127 could allow an unauthenticated remote code execution, compromising the entire system.

4

Which software is affected by CVE-2026-58127?

CVE-2026-58127 affects PACSgear MediaWriter version 5.2.1.

5

What is the exposure vector for CVE-2026-58127?

CVE-2026-58127 is exposed over the network, specifically on port 9000 without authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203