Full Disclosure mailing list archives
Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)
From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:04:30 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH). The research is published and a proof-of-concept is available. Pre-authentication RCE (BinaryFormatter deserialization) (CVSS 9.8, pre-authentication) Cinegy Cinegize (2026-02-05 installer) registers a Windows service listening on TCP 51140 with a DotNetty pipeline that deserializes .NET BinaryFormatter objects before the authorization handler runs. An unauthenticated remote attacker sends a TypeConfuseDelegate gadget frame; deserialization triggers Process.Start as LocalSystem. No authentication, no license gate, and a default inbound firewall rule make the service reachable in a default install. Dynamically verified. Impact: Full compromise of the broadcast and media-workflow automation host as LocalSystem. The attacker can disrupt broadcast operations, execute arbitrary commands, and access media assets. Advisory: https://0day-rubbish.com/blog/cinegy-cinegize-unauth-binaryformatter-rce PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish Vendor has been notified. CVE ID is pending. -- 0day Rubbish Research Team https://0day-rubbish.com _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH) disclosure via Fulldisclosure (Aug 17)
