Impact
An attacker can trigger the execution of arbitrary code on the affected system by providing a specially crafted dynamic link library file. This flaw allows the remote execution of code with the privileges of the target application, potentially compromising confidentiality, integrity, and availability of the system. The vulnerability’s core weakness aligns with code injection and execution abuse.
Affected Systems
CompuGroup Medical CGM ISIS MED version 2510.1.0.20, sold and operated in Germany by CGM Germany. No other affected products or editions are specified.
Risk and Exploitability
The CVE has no EPSS score or CVSS rating listed, and it is not present in the CISA KEV catalog, indicating a low public exploitation footprint as of the available data. However, the lack of mitigation from the vendor means the flaw could still be leveraged by attackers who can supply the malicious DLL, typically via remote upload or remote execution channels. The vector is inferred to be remote file manipulation given the nature of the exploit.
OpenCVE Enrichment