PT-2018-18665 · Philips+1 · Brilliance 64+3
Published
2018-05-04
·
Updated
2019-10-09
·
CVE-2018-8853
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Philips Brilliance CT devices versions prior to the following:
Brilliance 64 version 2.6.2
Brilliance iCT version 4.1.6
Brilliance iCT SP version 3.2.4
Brilliance CT Big Bore version 2.3.5
Description
The issue allows a kiosk application, user, or an attacker to potentially attain unauthorized elevated privileges due to the default boot configuration of the Microsoft Windows operating system with elevated Windows privileges. This could also enable attackers to gain access to unauthorized resources from the underlying Windows operating system.
Recommendations
For Brilliance 64 version 2.6.2 and prior, update to a version later than 2.6.2 to resolve the issue.
For Brilliance iCT versions 4.1.6 and prior, update to a version later than 4.1.6 to resolve the issue.
For Brilliance iCT SP versions 3.2.4 and prior, update to a version later than 3.2.4 to resolve the issue.
For Brilliance CT Big Bore version 2.3.5 and prior, update to a version later than 2.3.5 to resolve the issue.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brilliance 64
Brilliance Ct Big Bore
Brilliance Ict
Windows