From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:04:30 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Cinegy Cinegize 2026-02-05 installer (Cinegy
GmbH). The research is published and a proof-of-concept is available.
Pre-authentication RCE (BinaryFormatter deserialization) (CVSS 9.8, pre-authentication)
Cinegy Cinegize (2026-02-05 installer) registers a Windows service listening on TCP 51140 with a DotNetty pipeline that
deserializes .NET BinaryFormatter objects before the authorization handler runs. An unauthenticated remote attacker
sends a TypeConfuseDelegate gadget frame; deserialization triggers Process.Start as LocalSystem. No authentication, no
license gate, and a default inbound firewall rule make the service reachable in a default install. Dynamically verified.
Impact: Full compromise of the broadcast and media-workflow automation host as LocalSystem. The attacker can disrupt
broadcast operations, execute arbitrary commands, and access media assets.
Advisory: https://0day-rubbish.com/blog/cinegy-cinegize-unauth-binaryformatter-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
Vendor has been notified. CVE ID is pending.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH) disclosure via Fulldisclosure (Aug 17)