Welcome to the March 2025 MEDITECH Customer Security Newsletter, where we provide you with information and resources to give you insight on security challenges facing your organization and the healthcare community as a whole. Here we endeavor to provide some good information to help you improve your organization's security posture. This data has been gleaned from the review of public records on file with CISA, H-ISAC and Health Sector Cybersecurity Coordination Center (HC3) alerts. Please note the Talk To Us section, as we would like to tailor future editions of the newsletter to address specific concerns.
Known Exploited Vulnerabilities
From February 13, 2025 until the writing of this bulletin, there have been thirty known exploited vulnerabilities added to CISA's list . They are CVE-2017-3066, CVE-2018-8639,CVE-2022-43769,CVE-2022-43939,CVE-2023-20118,CVE-2023-34192,CVE-2024-4885,CVE-2024-13159,CVE-2024-13160,CVE-2024-13161,CVE-2024-20953,CVE-2024-49035,CVE-2024-50302,CVE-2024-53704,CVE-2024-57727,CVE-2024-57968,CVE-2025-0108,CVE-2025-0111, CVE-2025-22224,CVE-2025-22225,CVE-2025-22226,CVE-2025-23209,CVE-2025-24983,CVE-2025-24984,CVE-2025-24985,CVE-2025-24989,CVE-2025-24991,CVE-2025-24993,CVE-2025-25181 and CVE-2025-26633.
All of these additions are based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks. When looking at the catalog, the CVEs are listed from most recently added by default and the list may be manipulated by using the provided filters. This list was most recently reviewed on March 12, 2025.
Vulnerabilities for Hospitals to Watch Out For
These significant vulnerabilities have been shown to have been weaponized in February and March 2025. Intelligence indicates a high degree of caution for hospital infrastructures.
- CVE-2025-26633 (HIGH): This vulnerability in the Windows Management Console (MMC) allows improper neutralization
- CVE-2025-0411 (HIGH) This 7-Zip vulnerability allows attackers to bypass protection mechanisms, enabling the execution of malicious files without user warnings
- These Windows vulnerabilities, primarily affecting NTFS and Win32k, allow for privilege escalation, information disclosure, and remote code execution
- CVE-2025-24983 (HIGH)
- CVE-2025-24984 (MEDIUM)
- CVE-2025-24985 (HIGH)
- CVE-2025-24991 (MEDIUM)
- CVE-2025-24993 (HIGH)
News
Guidance and Strategies to Protect Network Edge Devices
2024 Health-ISAC Discussion Based Exercise Series After-Action Report
On March 11, H-ISAC published a white paper outlining the best practices for continuous improvement in cybersecurity and preparedness for the helth sector.
Additional Resources
- HHS 405(d) Aligning Health Care Industry Security Approaches - The 405(d) Program and Task Group is a collaborative effort between industry and the federal government, which aims to raise awareness, provide vetted cybersecurity practices, and move healthcare organizations towards consistency in mitigating the current most pertinent cybersecurity threats to the sector. Their website provides the latest resources and information as well as an opportunity for involvement.
- Helpful resources CISA has provided can be found on the following pages:
Talk to us!
We at MEDITECH would love to hear your feedback about this newsletter and we’d like to know what is on your mind. Is there something you would like us to address?
We also have a question for you that is important to us. What are your largest concerns or security hopes for 2024?
Please let us know by contacting us!
Until next time, stay alert out there!