A high-severity vulnerability, tracked as CVE-2024-22774, was discovered in the AJAT Panoramic Dental Imaging Software SDK, now owned by Varex Imaging. The flaw, caused by an uncontrolled search path element (CWE-427), allows for DLL hijacking, enabling a standard user to escalate privileges and obtain NT Authority/SYSTEM access via the ccsservice.exe component. The vulnerability affects software versions prior to 6.6.1.490 and was identified by security researcher Damian Semon Jr. of Blue Team Alpha Inc. Both the vendor and the Cybersecurity and Infrastructure Security Agency (CISA) have issued advisories, rating the issue as high-severity with a CVSS v4 base score of 8.5 and a CVSS v3.1 score of 7.8.
Varex Imaging has released a patch to address the vulnerability and strongly advises all users to update their systems by running the installation executable on each affected workstation. CISA further recommends placing the software behind a firewall, restricting Internet access, and using secure remote access methods such as up-to-date VPNs. The vulnerability is particularly relevant to the healthcare and public health sectors, with deployments primarily in North America. Organizations using the affected software should prioritize patching to mitigate the risk of privilege escalation attacks.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CISA issued ICS medical advisory ICSMA-25-345-02 covering the high-severity vulnerability, noting it is not remotely exploitable and that there were no known reports of public exploitation. The agency also recommended mitigations such as network segmentation, firewalling, and secure remote access practices.
Varex Imaging released a fix for Panoramic Dental Imaging Software versions prior to 6.6.1.490 to remediate the privilege-escalation flaw. The update must be installed on each affected workstation.
Damian Semon Jr. of Blue Team Alpha Inc. identified CVE-2024-22774, an uncontrolled search path element vulnerability in AJAT/Varex Panoramic Dental Imaging Software that could allow DLL hijacking and privilege escalation to NT AUTHORITY\SYSTEM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.