Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)
Full Disclosuremailing list archivesFrom: disclosure via Fulldisclosure <fulldis 2026-8-18 06:17:41 Author: seclists.org(查看原文) 阅读量:3 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:04:30 +0000

0day Rubbish Research Team is publicly disclosing a vulnerability in Cinegy Cinegize 2026-02-05 installer (Cinegy 
GmbH). The research is published and a proof-of-concept is available.

Pre-authentication RCE (BinaryFormatter deserialization) (CVSS 9.8, pre-authentication)

Cinegy Cinegize (2026-02-05 installer) registers a Windows service listening on TCP 51140 with a DotNetty pipeline that 
deserializes .NET BinaryFormatter objects before the authorization handler runs. An unauthenticated remote attacker 
sends a TypeConfuseDelegate gadget frame; deserialization triggers Process.Start as LocalSystem. No authentication, no 
license gate, and a default inbound firewall rule make the service reachable in a default install. Dynamically verified.

Impact: Full compromise of the broadcast and media-workflow automation host as LocalSystem. The attacker can disrupt 
broadcast operations, execute arbitrary commands, and access media assets.

Advisory: https://0day-rubbish.com/blog/cinegy-cinegize-unauth-binaryformatter-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH) disclosure via Fulldisclosure (Aug 17)

文章来源: https://seclists.org/fulldisclosure/2026/Aug/60
如有侵权请联系:admin#unsafe.sh