Varex Imaging and Panoramic Corporation got ICSMA-25-345-02 for dental imaging software before 6.6.1.490. CVE-2024-22774, an uncontrolled search path element in ccsservice.exe, or in plain name, DLL hijacking. A standard user drops a malicious DLL where the service looks for it and rides it up to NT AUTHORITY\SYSTEM. CVSS v4 8.5.

It sounds mild until you remember shared clinical workstations rarely give each user their own machine. Damian Semon Jr. of Blue Team Alpha reported it. If your Windows service loads libraries by name, pin the path. The default search order is an attacker convenience.