← Back to browse · API

CVE-2025-34153

Severity
CRITICAL
CVSS
10.0
EPSS
0.00653
Risk score
40.23
CISA KEV
No
PoC
No
Published
2025-08-13
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2025-24595, GHSA-4VJP-PHJJ-3F57
Products
Hyland Software:OnBase 0 <17.0.2.87
Sources
euvd EUVD-2025-24595

Description

Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031 with the URI endpoint TimerServer, implemented in Hyland.Core.Timers.dll. This endpoint deserializes untrusted input using the .NET BinaryFormatter, allowing attackers to execute arbitrary code under the context of NT AUTHORITY\SYSTEM.

References