Executive brief
Nuance PowerScribe, a widely used radiology reporting and dictation platform, contains a critical security flaw. An unauthorized attacker can remotely take control of the system by sending specially crafted data over the network. This could lead to the theft of sensitive patient data, disruption of medical reporting services, or full system compromise.
Technical details
A critical deserialization vulnerability (CWE-502) exists in Nuance PowerScribe. The flaw stems from the application improperly processing untrusted data, allowing an attacker to trigger the execution of arbitrary code. This attack can be carried out over the network without any prior authentication or user interaction. Successful exploitation grants the attacker high-level access to the underlying system, potentially leading to full confidentiality, integrity, and availability loss. Users are advised to consult Microsoft/Nuance security updates for patching information.
Affected products
- Nuance PowerScribe
Timeline
- 2026-06-09: disclosed: Initial disclosure by Microsoft Corporation
- 2026-06-09: advisory: NVD record published