Panoramic Digital Imaging Software 9.1.2.7600 got ICSMA-25-198-01. CVE-2024-22774, an uncontrolled search path, DLL hijacking, letting a standard local user climb to NT AUTHORITY\SYSTEM. Damian Semon Jr. of Blue Team Alpha reported it.
DLL hijacking exploits the ordered way the operating system searches for a library requested only by name. If that search reaches a directory an unprivileged user can write to before it reaches the legitimate location, a planted file with the expected name loads in place of the real one. When the program loading that library runs with elevated rights, the attacker's code inherits them.
A local escalation earns attention on clinical software because of the environment it runs in. Imaging tools in a practice frequently sit on shared machines that staff sign into with limited accounts by design. A path from a standard user to full system control erases that boundary, and from there an intruder can switch off protections, reach stored images, or use the workstation as a foothold into the wider clinic network.
On its own an escalation like this is not a remote break-in; it presumes the attacker already runs code on the machine as an ordinary user. In a networked clinic that precondition is not a high bar, since a phished document, a malicious upload or a shared login can supply the initial foothold. The value of the flaw is that it converts modest access into complete control of the host, the step that turns a nuisance into a compromise.
The origin matters more than the bug. It was inherited from an unsupported SDK component from another vendor. The dental imaging maker did not write it, but it shipped it, and its customers run it. Unsupported dependencies are unpatched dependencies, and when the upstream is dead its bugs become permanent unless you rip the component out.
Track the support status of every third-party component, not just its version. An end-of-life SDK will not fix itself, and its CVEs become yours to answer for.