Mckesson · Mckesson Cardiology · CVE-2018-18630
**Name of the Vulnerable Software and Affected Versions**
McKesson Cardiology versions 13.x through 14.x
**Description**
A vulnerability was found in the McKesson Cardiology product due to insecure file permissions in the default installation. This may allow an attacker with local system access to execute unauthorized arbitrary code.
**Recommendations**
For versions 13.x through 14.x, update the file permissions to secure settings to prevent unauthorized access. As a temporary workaround, consider restricting local system access to minimize the risk of exploitation.