Impact
An attacker can trigger the execution of arbitrary code on the affected system by providing a specially crafted dynamic link library file. This flaw allows the remote execution of code with the privileges of the target application, potentially compromising confidentiality, integrity, and availability of the system. The vulnerability’s core weakness aligns with code injection and execution abuse.
Affected Systems
CompuGroup Medical CGM ISIS MED version 2510.1.0.20. No other affected products or editions are specified.
Risk and Exploitability
The CVE has an EPSS score of <1% and a CVSS score of 7.8, and it is not present in the CISA KEV catalog, indicating a low public exploitation footprint as of the available data. No official mitigation is publicly announced, so the flaw could still be leveraged by attackers who can supply the malicious DLL, typically via remote upload or remote execution channels. The vector is inferred to be remote file manipulation given the nature of the exploit.
OpenCVE Enrichment