First published: Tue Aug 14 2018(Updated: )
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated privileges could access folders which contain executables where authenticated users have write permissions, and could then execute arbitrary code with local administrative permissions.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips IntelliSpace Cardiovascular | <=3.1 | |
Philips Xcelera | <=4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14787 is considered a high-severity vulnerability due to the potential for arbitrary code execution by an authenticated user.
To mitigate CVE-2018-14787, upgrade Philips IntelliSpace Cardiovascular to version 3.1 or later and Philips Xcelera to version 4.2 or later.
CVE-2018-14787 affects users of Philips IntelliSpace Cardiovascular versions 2.x and prior, and Philips Xcelera versions 4.1 and prior.
Exploitation of CVE-2018-14787 could allow an attacker with escalated privileges to execute arbitrary code on affected systems.
An attacker can exploit CVE-2018-14787 by gaining elevated privileges to access executable folders and leveraging write permissions to execute malicious code.