Change Healthcare Cardiology ACE Vulnerability
Change Healthcare have released details of an incorrect default permissions vulnerability affecting their Change Healthcare, Horizon, and McKesson Cardiology products.
Summary
Change Healthcare have released details of an incorrect default permissions vulnerability affecting their Change Healthcare, Horizon, and McKesson Cardiology products.
Threat details
A local, authenticated user could exploit this vulnerability to execute arbitrary code.
The vulnerability is a result of files being assigned insecure permissions during the default installation process. An attacker could insert specially crafted files to this process, which may result in arbitrary code execution (ACE).
For further information:
Remediation steps
CVE Vulnerabilities
Last edited: 14 February 2020 2:58 pm