Pacsgear · Pacsgear Pacs Scan · CVE-2026-58126
**Name of the Vulnerable Software and Affected Versions**
PACSgear PACS Scan version 5.2.1
**Description**
An unauthenticated remote code execution issue exists due to an exposed .NET Remoting TCP service on port 22222 used by `PGImageExchQueue.exe`. The flaw stems from insecure remoting endpoints and improper authentication and access control, allowing remote attackers to read and write arbitrary files. This capability can be chained with DLL hijacking in `PGImageExchangeQueueSvc.exe`, which loads missing DLLs such as `CRYPTSP.DLL` from the application directory. Upon service restart, this allows for remote code execution with NT AUTHORITYSYSTEM privileges, potentially leading to complete host takeover, lateral movement, and data theft in clinical imaging environments.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.