Skip to main content

Change Healthcare Cardiology ACE Vulnerability

Change Healthcare have released details of an incorrect default permissions vulnerability affecting their Change Healthcare, Horizon, and McKesson Cardiology products.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Change Healthcare have released details of an incorrect default permissions vulnerability affecting their Change Healthcare, Horizon, and McKesson Cardiology products.


Threat details

A local, authenticated user could exploit this vulnerability to execute arbitrary code.

The vulnerability is a result of files being assigned insecure permissions during the default installation process. An attacker could insert specially crafted files to this process, which may result in arbitrary code execution (ACE).

For further information:


Remediation steps

Type Step

Change Healthcare have confirmed that updates for the affected platforms have been made available. Affected organisations are encouraged to contact their relevant suppliers to acquire and apply these patches immediately.



CVE Vulnerabilities

Last edited: 14 February 2020 2:58 pm