CVE-2025-64642
8.0Mirion Medical · NMIS/BioDose
Mirion Medical NMIS/BioDose V22.02 and earlier versions contain insecure default file permissions, allowing local users to modify critical program executables and libraries.
Executive summary
Insecure default file permissions in Mirion Medical NMIS/BioDose allow local users to modify critical software components, potentially leading to unauthorized code execution and system compromise.
Vulnerability
This vulnerability involves an incorrect permission assignment for critical resources (CWE-732). The software installs with default permissions that allow unauthenticated local users on client workstations to modify executables and libraries.
Business impact
The vulnerability carries a CVSS score of 8.0, reflecting its high impact on system integrity and availability. If an attacker gains local access to a workstation, they can replace program binaries with malicious code, potentially resulting in full system compromise or the subversion of medical data processing. This poses significant operational and safety risks to healthcare environments relying on this software.
Remediation
Immediate Action: Update the NMIS/BioDose software to version 23.0 or later as recommended by Mirion Medical. Users should reach out to their support representative to facilitate this update process.
Proactive Monitoring: Monitor workstation file integrity logs for unauthorized modifications to the installation directory. Review access control lists for the application folder to ensure only authorized service accounts have write permissions.
Compensating Controls: Implement strict endpoint security policies that restrict local user privileges and prevent unauthorized execution of modified binaries. Use host-based intrusion detection systems to alert on changes to sensitive application directories.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability presents a significant risk to the integrity of medical software installations. Administrators must prioritize upgrading to version 23.0 immediately to remediate the insecure permission structure. Until the update is applied, ensure that local user permissions on all client workstations are restricted to the minimum necessary level to prevent unauthorized access to the application directory.
Sources
Originally found and disclosed by Joe Dillon reported these vulnerabilities to Mirion Medical., per the CVE Program record.