Description
An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application can decrypt credentials stored in a configuration-related registry key. An attacker can execute a malicious script or application to exploit this vulnerability.
Problem types
CWE-732: Incorrect Permission Assignment for Critical Resource
Product status
Credits
Discovered by Emmanuel Tacheau of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2025-2154
talosintelligence.com/vulnerability_reports/TALOS-2025-2154