CVE-2025-30398
8.1Microsoft · Nuance PowerScribe 360
A missing authorization vulnerability in Microsoft Nuance PowerScribe 360 allows unauthenticated attackers to perform unauthorized information disclosure over a network.
Executive summary
An unauthenticated remote attacker can exploit a missing authorization flaw in Microsoft Nuance PowerScribe 360 to access sensitive information, posing a significant risk to data confidentiality.
Vulnerability
This vulnerability involves a failure to perform proper authorization checks (CWE-862), which allows an unauthenticated attacker to interact with the application and disclose data.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high level of severity. Successful exploitation could lead to the exposure of sensitive medical or administrative data, resulting in potential regulatory non-compliance, loss of patient privacy, and significant reputational damage to the healthcare organization.
Remediation
Immediate Action: Apply the vendor-supplied security updates referenced in the Microsoft Security Update Guide immediately to remediate the authorization deficiency.
Proactive Monitoring: Review system and application access logs for unusual network activity or unauthorized requests originating from internal or external sources.
Compensating Controls: Implement network segmentation and restrict access to the Nuance PowerScribe interface to trusted IP ranges only to reduce the attack surface until patches are applied.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Given the high CVSS score and the nature of the data handled by Nuance PowerScribe, organizations should treat this vulnerability with high urgency. Administrators must prioritize the deployment of the vendor updates to ensure that authorization controls are correctly enforced and sensitive information is protected from unauthorized access.
More Microsoft CVEs
Sources
- Nuance PowerScribe 360 Information Disclosure Vulnerability Vendor advisory