CVE-2024-23622: IBM Merge Healthcare eFilm Workstation License Server CopySLS_Request3 Buffer Overflow
Published Jan 25, 2024
·Updated
A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution with SYSTEM privileges.
Affected Software
1 affected component
IBM Merge Efilm Workstation<=4.2
Event History
Jan 25, 2024
CVE Published
via MITRE·11:36 PM
Data Sourced
via MITRE·11:36 PM
DescriptionSeverityWeakness
Jan 26, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23622?
CVE-2024-23622 is rated as high severity due to the potential for remote code execution with SYSTEM privileges.
2
How do I fix CVE-2024-23622?
To fix CVE-2024-23622, users should upgrade to the latest version of IBM Merge Healthcare eFilm Workstation beyond version 4.2.
3
What type of attacker can exploit CVE-2024-23622?
CVE-2024-23622 can be exploited by a remote, unauthenticated attacker.
4
What kind of vulnerability is CVE-2024-23622?
CVE-2024-23622 is a stack-based buffer overflow vulnerability.
5
Which software is affected by CVE-2024-23622?
CVE-2024-23622 affects IBM Merge Healthcare eFilm Workstation versions up to and including 4.2.