Impact
PACSgear PACS Scan 5.2.1 contains an unauthenticated flaw that enables remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222. The service is invoked by PGImageExchQueue.exe and accepts crafted requests without authentication, exposing a CWE‑306 weakness. By supplying a specially crafted payload, an attacker can inject a malicious DLL into the application directory and then trigger a restart of PGImageExchangeQueueSvc.exe, whose DLL load order allows the injected package to run as NT Authority\\SYSTEM, providing full system control.
Affected Systems
Hyland PACSgear PACS Scan 5.2.1 is the affected version; no other releases have been confirmed to be affected at this time.
Risk and Exploitability
The flaw scores a CVSS score of 9.3, marking it as critical. It can be reached over the network without authentication by connecting to TCP port 22222, which is the likely attack vector. The EPSS score of < 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs remote network access to the host, no local privileges, to send a crafted payload, stage the file‑write and DLL hijack sequence, and then wait for the service restart to gain SYSTEM rights.
OpenCVE Enrichment