PT-2018-18665 · Philips+1 · Brilliance 64+3

Published

2018-05-04

·

Updated

2019-10-09

·

CVE-2018-8853

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Philips Brilliance CT devices versions prior to the following: Brilliance 64 version 2.6.2 Brilliance iCT version 4.1.6 Brilliance iCT SP version 3.2.4 Brilliance CT Big Bore version 2.3.5
Description The issue allows a kiosk application, user, or an attacker to potentially attain unauthorized elevated privileges due to the default boot configuration of the Microsoft Windows operating system with elevated Windows privileges. This could also enable attackers to gain access to unauthorized resources from the underlying Windows operating system.
Recommendations For Brilliance 64 version 2.6.2 and prior, update to a version later than 2.6.2 to resolve the issue. For Brilliance iCT versions 4.1.6 and prior, update to a version later than 4.1.6 to resolve the issue. For Brilliance iCT SP versions 3.2.4 and prior, update to a version later than 3.2.4 to resolve the issue. For Brilliance CT Big Bore version 2.3.5 and prior, update to a version later than 2.3.5 to resolve the issue.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8853

Affected Products

Brilliance 64
Brilliance Ct Big Bore
Brilliance Ict
Windows