PT-2025-33029 · Hyland · Hyland Onbase

Victor Morales

·

Published

1999-01-01

·

Updated

2026-02-13

·

CVE-2025-34153

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Hyland OnBase versions prior to 17.0.2.87
Description: Hyland OnBase is vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031 with the URI endpoint TimerServer, implemented in Hyland.Core.Timers.dll. This endpoint deserializes untrusted input using the .NET BinaryFormatter, allowing attackers to execute arbitrary code under the context of NT AUTHORITYSYSTEM.
Recommendations: Update Hyland OnBase to version 17.0.2.87 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-34153
DOTNETREMOTINGCHECK

Affected Products

Hyland Onbase