First published: Fri May 04 2018(Updated: )
Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) could enable a limited-access kiosk user or an unauthorized attacker to break-out from the containment of the kiosk environment, attain elevated privileges from the underlying Windows OS, and access unauthorized resources from the operating system.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Brilliance Firmware 64 | <=2.6.2 | |
Philips Brilliance Firmware 64 | ||
Philips Brilliance Ict | <=3.2.4 | |
Philips Brilliance | ||
Philips Brilliance | <=4.1.6 | |
Philips Brilliance ICT | ||
Philips Brilliance CT Big Bore Firmware | <=2.3.5 | |
Philips Brilliance CT Big Bore |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8861 has been categorized as a low severity vulnerability.
To mitigate CVE-2018-8861, upgrade the affected Philips Brilliance CT kiosk software to the latest versions available.
CVE-2018-8861 affects Philips Brilliance 64 versions up to 2.6.2, Brilliance iCT versions up to 4.1.6, Brilliance iCT SP versions up to 3.2.4, and Brilliance CT Big Bore versions up to 2.3.5.
Limited-access kiosk users and unauthorized attackers could potentially exploit CVE-2018-8861.
CVE-2018-8861 is a vulnerability that allows limited-access users to potentially gain unauthorized access to sensitive settings.