CVE-2018-14787: High severity Philips IntelliSpace Cardiovascular vulnerability
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated privileges could access folders which contain executables where authenticated users have write permissions, and could then execute arbitrary code with local administrative permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14787?
CVE-2018-14787 is considered a high-severity vulnerability due to the potential for arbitrary code execution by an authenticated user.
How do I fix CVE-2018-14787?
To mitigate CVE-2018-14787, upgrade Philips IntelliSpace Cardiovascular to version 3.1 or later and Philips Xcelera to version 4.2 or later.
Who is affected by CVE-2018-14787?
CVE-2018-14787 affects users of Philips IntelliSpace Cardiovascular versions 2.x and prior, and Philips Xcelera versions 4.1 and prior.
What are the potential impacts of CVE-2018-14787?
Exploitation of CVE-2018-14787 could allow an attacker with escalated privileges to execute arbitrary code on affected systems.
How can an attacker exploit CVE-2018-14787?
An attacker can exploit CVE-2018-14787 by gaining elevated privileges to access executable folders and leveraging write permissions to execute malicious code.