IBM Merge Healthcare eFilm Workstation License Server CopySLS_Request3 Buffer Overflow
CVE-2024-23622

10CRITICAL

Key Information:

Vendor
CVE Published:
26 January 2024

What is CVE-2024-23622?

A stack-based buffer overflow vulnerability has been identified in the IBM Merge Healthcare eFilm Workstation license server. This flaw allows a remote, unauthenticated attacker to exploit the server, with the potential to gain remote code execution capabilities under SYSTEM privileges. Given the nature of the vulnerability, it poses significant security risks, particularly in environments where the eFilm Workstation is deployed. Organizations utilizing this software should take immediate measures to safeguard their systems and mitigate any potential threats.

Affected Version(s)

eFilm Workstation 4.1 <= 4.2

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Exodus Intelligence
.