Varex Imaging and Panoramic Corporation got ICSMA-25-345-02 for dental imaging software before 6.6.1.490. CVE-2024-22774, an uncontrolled search path element in ccsservice.exe, or in plain name, DLL hijacking. A standard user drops a malicious DLL where the service looks for it and rides it up to NT AUTHORITY\SYSTEM. CVSS v4 8.5.
Uncontrolled search path weaknesses trace back to how the Windows loader resolves a library requested by name. The operating system walks an ordered list of directories looking for a matching file, and a program that names a dependency without pinning its full location can be steered toward whatever copy appears first. A standard account able to write to one of those earlier directories controls what code the privileged process loads.
The escalation is what gives the finding its weight. Imaging services on clinical Windows machines frequently run under the most privileged system account so they can reach hardware and shared storage without prompting, which means a library planted by an ordinary user executes with that same reach. On a dental imaging station the captured radiographs, the stored studies and the credentials cached on the box all sit inside that boundary.
It sounds mild until you remember shared clinical workstations rarely give each user their own machine. Damian Semon Jr. of Blue Team Alpha reported it. If your Windows service loads libraries by name, pin the path. The default search order is an attacker convenience.
Local privilege-escalation findings like this one usually emerge from a security firm's hands-on assessment rather than from a failure noticed in the clinic, since nothing visibly breaks while the flaw sits in the loader's default behavior. They reach practices through a coordinated advisory that names the affected software and the corrected build, the standard route for turning a quiet weakness into something a buyer can act on.