Panoramic Digital Imaging Software 9.1.2.7600 got ICSMA-25-198-01. CVE-2024-22774, an uncontrolled search path, DLL hijacking, letting a standard local user climb to NT AUTHORITY\SYSTEM. Damian Semon Jr. of Blue Team Alpha reported it.
The origin matters more than the bug. It was inherited from an unsupported SDK component from another vendor. The dental imaging maker did not write it, but it shipped it, and its customers run it. Unsupported dependencies are unpatched dependencies, and when the upstream is dead its bugs become permanent unless you rip the component out.
Track the support status of every third-party component, not just its version. An end-of-life SDK will not fix itself, and its CVEs become yours to answer for.