Philips IntelliSpace Perinatal Privilege Escalation Vulnerability
Philips Healthcare has released details of a privilege escalation vulnerability affecting their IntelliSpace Perinatal obstetrics information management system. A local unauthenticated user could exploit this vulnerability to extract information, execute files, or alter system configurations.
Summary
Philips Healthcare has released details of a privilege escalation vulnerability affecting their IntelliSpace Perinatal obstetrics information management system. A local unauthenticated user could exploit this vulnerability to extract information, execute files, or alter system configurations.
Threat details
A local unauthenticated user could exploit this vulnerability to extract information, execute files, or alter system configurations. The vulnerability is a result of the IntelliSpace Perinatal application server not sufficiently limiting exposure of it's own resources. An attacker with physical access or using a remote desktop host could exploit this to gain access to both the application server and the underlying operating system (typically Microsoft Windows). Patient identifiable information can also be accessed if the Document Export (DOX) functionality is enabled on the application server.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
At the publication, Philips have not confirmed if updates will be made available for the affected versions of IntelliSpace Perinatal. However, they have recommended affected organisations take the following actions to partially mitigate the threat:
|
CVE Vulnerabilities
Last edited: 14 February 2020 2:57 pm