CVE-2024-23620

An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vulnerability to escalate privileges to SYSTEM.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:merge_efilm_workstation:*:*:*:*:*:*:*:*

History

31 Jan 2024, 20:29

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:merge_efilm_workstation:*:*:*:*:*:*:*:*
First Time Ibm
Ibm merge Efilm Workstation
CVSS v2 : 6.8
v3 : 8.8
v2 : 6.8
v3 : 7.8
References () https://blog.exodusintel.com/2024/01/25/ibm-merge-healthcare-efilm-workstation-system-privilege-escalation/ - () https://blog.exodusintel.com/2024/01/25/ibm-merge-healthcare-efilm-workstation-system-privilege-escalation/ - Third Party Advisory

26 Jan 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de gestión de privilegios inadecuada en IBM Merge Healthcare eFilm Workstation. Un atacante local autenticado puede aprovechar esta vulnerabilidad para escalar privilegios al SISTEMA.

26 Jan 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 00:15

Updated : 2024-01-31 20:29


NVD link : CVE-2024-23620

Mitre link : CVE-2024-23620

CVE.ORG link : CVE-2024-23620


JSON object : View

Products Affected

ibm

  • merge_efilm_workstation
CWE
CWE-269

Improper Privilege Management