CVE-2024-23622

A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution with SYSTEM privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:merge_efilm_workstation:*:*:*:*:*:*:*:*

History

31 Jan 2024, 20:30

Type Values Removed Values Added
References () https://blog.exodusintel.com/2024/01/25/ibm-merge-healthcare-efilm-workstation-license-server-copysls_request3-buffer-overflow/ - () https://blog.exodusintel.com/2024/01/25/ibm-merge-healthcare-efilm-workstation-license-server-copysls_request3-buffer-overflow/ - Third Party Advisory
CWE CWE-787
CPE cpe:2.3:a:ibm:merge_efilm_workstation:*:*:*:*:*:*:*:*
CVSS v2 : 10.0
v3 : 10.0
v2 : 10.0
v3 : 9.8
First Time Ibm
Ibm merge Efilm Workstation

26 Jan 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Existe un desbordamiento de búfer en la región stack de la memoria en el servidor de licencias de IBM Merge Healthcare eFilm Workstation. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para lograr la ejecución remota de código con privilegios de SYSTEM.

26 Jan 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 00:15

Updated : 2024-01-31 20:30


NVD link : CVE-2024-23622

Mitre link : CVE-2024-23622

CVE.ORG link : CVE-2024-23622


JSON object : View

Products Affected

ibm

  • merge_efilm_workstation
CWE
CWE-787

Out-of-bounds Write

CWE-131

Incorrect Calculation of Buffer Size