Executive brief
CGM ISIS MED is a medical practice management software used by healthcare facilities to manage patient records and clinical operations. The software loads DLL libraries from a folder where low-privileged users have write access, allowing attackers to place malicious DLLs that execute with the application's privileges. An attacker can exploit this to execute arbitrary code and gain elevated privileges on affected systems.
Technical details
The vulnerability is a DLL hijacking issue in CGM ISIS MED version 2510.1.0.20. The affected component is the SILoader.exe application, which attempts to load DLL files from the AppData\Local\Apps directory. Due to improper permission controls, the target directory allows write access to local users. An attacker with local access can place a malicious DLL (e.g., dfshim.dll) in the search path, causing the application to load and execute the attacker-supplied code with the same privileges as the application. No authentication or network access is required; only local file write access is needed. The impact is arbitrary code execution and potential privilege escalation. A patch or updated version has not yet been identified in the available advisory material.
Affected products
- CompuGroup Medical CGM ISIS MED 2510.1.0.20
Timeline
- 2026-08-17: disclosed