Executive brief
Nuance PowerScribe is a medical reporting and speech recognition platform used by healthcare providers to document patient findings. A security flaw in this system allows an unauthorized person to access and disclose sensitive information over the network. This could lead to the exposure of private patient data or unauthorized modification of records, potentially impacting clinical operations and patient privacy.
Technical details
A missing authorization vulnerability (CWE-862) exists in Microsoft Nuance PowerScribe One and PowerScribe 360. The flaw allows an unauthenticated attacker to disclose or modify information over a network, provided there is some level of user interaction. According to the CVSS vector, the attack is low complexity and can be executed remotely, resulting in high impacts on confidentiality and integrity. Microsoft has released security updates to address this issue across various versions of the PowerScribe product line.
Affected products
- Microsoft Nuance PowerScribe One 2019.1 through 2023.1 SP2 Patch 7
- Microsoft Nuance PowerScribe 360 4.0.1 through 4.0.9
Timeline
- 2025-11-11: disclosed
- 2025-11-11: advisory