PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-22774 Panoramic Corporation CVE debrief

CVE-2024-22774 affects Panoramic Corporation Digital Imaging Software and is described by CISA as a DLL hijacking issue that may allow a standard user to obtain NT AUTHORITY/SYSTEM. The advisory was published on 2025-07-17, and the source notes that Panoramic did not provide a specific mitigation; affected users are directed to contact support and apply defensive hardening measures.

Vendor
Panoramic Corporation
Product
Digital Imaging Software
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-07-17
Original CVE updated
2025-07-17
Advisory published
2025-07-17
Advisory updated
2025-07-17

Who should care

Organizations running Panoramic Corporation Digital Imaging Software, especially Windows administrators, security teams, and operators responsible for endpoint hardening and privilege management.

Technical summary

The advisory describes a local DLL hijacking weakness in Digital Imaging Software. The supplied CVSS vector indicates low-privilege, no-user-interaction local exploitation with high impacts to confidentiality, integrity, and availability. The source also states the vulnerable functionality is tied to an SDK component owned by Oy Ajat Ltd. that is no longer supported, and Panoramic did not recommend a product-specific mitigation.

Defensive priority

High. The issue can turn a standard user into NT AUTHORITY/SYSTEM on affected systems, which materially increases local takeover risk even though the attack is local and requires prior access to the host.

Recommended defensive actions

  • Inventory all systems running Panoramic Corporation Digital Imaging Software and identify the specific product instances affected.
  • Contact Panoramic Corporation support at [email protected] for product-specific guidance and any available update or replacement path.
  • Apply least-privilege controls on affected hosts and restrict standard users from modifying application directories or DLL search locations.
  • Review Windows application hardening and DLL loading protections to reduce DLL hijacking risk.
  • Follow CISA industrial control system defensive guidance and defense-in-depth practices for segmentation, access control, and system monitoring.
  • Monitor affected hosts for unexpected DLL loads, privilege elevation events, and changes in application directories or service execution behavior.

Evidence notes

CISA CSAF advisory ICSMA-25-198-01 states: "The affected product is vulnerable to DLL hijacking, which may allow an attacker to obtain NT Authority/SYSTEM as a standard user." The same source says the vulnerable SDK component is owned by Oy Ajat Ltd. and is no longer supported, and that Panoramic did not recommend any specific mitigation. The advisory and related reference materials were published on 2025-07-17.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-22774 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-22774

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-22774 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-22774

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-198-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-198-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.