invasive cardiology security website › ~ › media › downloads › us › support... · the...

65
GE Healthcare Page 1 of 65 GE Healthcare/September 18, 2014 Invasive Cardiology Security Website Interventional - Invasive Cardiology Product Group: Interventional Invasive Products Products: Mac-Lab IT/XT/XTi, CardioLab IT/XT/XTi, SpecialsLab and ComboLab IT/XT/XTi Recording Systems, Centricity Cardiology Data Management Systems Subject: Security Information Date: September 18, 2014 Summary The following information is provided to GE Healthcare Technologies customers in regards to known technical security vulnerabilities associated with Mac-Lab® Hemodynamic, CardioLab® Electrophysiology, SpecialsLab and ComboLab IT Recording Systems for Cath Lab, EP Lab and other interventional labs as well as the Centricity® Cardiology Data Management Systems. Security Patch Base Configuration The security patch base configuration of the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi product at release is listed within the MLCL Base Configuration under the Hemodynamic, Electrophysiology and Cardiovascular Information Technologies section of the http://www.gehealthcare.com/usen/security/products/modality_links.html website. Process The following actions are taken whenever Microsoft/OEMs releases new security patches: The Invasive Cardiology Engineering Team performs a security analysis process for supported Mac-Lab IT/XT/XTi, CardioLab IT/XT/XTi, GE Client Review and INW Server hardware/software. If a vulnerability meets Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi validation criteria, the vulnerability is communicated through the GEHC Product Security Database and Invasive Cardiology Security Website within two weeks of the patch release. Upon validation of the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability, the GEHC Product Security Database and Invasive Cardiology Security Website and affected Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi Security Patch Installation Instructions are updated. The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as follows: Any vulnerability that allows malware to alter or deny Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi functionality and/or infect and propagate through normal system use. Customers are responsible to stay informed with Microsoft vulnerability notifications and to visit the Invasive Cardiology websites to understand the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi impact. Once a security patch is validated, customers are responsible for the installation of security patches. All Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi Security Patch Installation Instructions are available on the Invasive Cardiology Security Website below the Validated Patches table. Vulnerabilities exposed after the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi product release which do not meet the criteria to be validated are not listed within the GEHC Product Security Database and Invasive Cardiology Security Website. These vulnerabilities are deemed to be non-critical and/or outside normal clinical workflow of the Mac-Lab

Upload: others

Post on 05-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 1 of 65 GE Healthcare/September 18, 2014

Invasive Cardiology Security Website Interventional - Invasive Cardiology

Product Group: Interventional Invasive Products

Products:

Mac-Lab IT/XT/XTi, CardioLab IT/XT/XTi, SpecialsLab and ComboLab IT/XT/XTi Recording Systems, Centricity Cardiology Data Management Systems

Subject: Security Information

Date: September 18, 2014

Summary

The following information is provided to GE Healthcare Technologies customers in regards to known technical

security vulnerabilities associated with Mac-Lab® Hemodynamic, CardioLab® Electrophysiology, SpecialsLab and

ComboLab IT Recording Systems for Cath Lab, EP Lab and other interventional labs as well as the Centricity®

Cardiology Data Management Systems.

Security Patch Base Configuration

The security patch base configuration of the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi product at release is listed

within the MLCL Base Configuration under the Hemodynamic, Electrophysiology and Cardiovascular Information

Technologies section of the http://www.gehealthcare.com/usen/security/products/modality_links.html website.

Process

The following actions are taken whenever Microsoft/OEMs releases new security patches:

The Invasive Cardiology Engineering Team performs a security analysis process for supported Mac-Lab

IT/XT/XTi, CardioLab IT/XT/XTi, GE Client Review and INW Server hardware/software.

If a vulnerability meets Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi validation criteria, the vulnerability is

communicated through the GEHC Product Security Database and Invasive Cardiology Security Website

within two weeks of the patch release.

Upon validation of the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability, the GEHC Product Security

Database and Invasive Cardiology Security Website and affected Mac-Lab IT/XT/XTi and CardioLab

IT/XT/XTi Security Patch Installation Instructions are updated.

The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as follows: Any vulnerability that

allows malware to alter or deny Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi functionality and/or infect and

propagate through normal system use.

Customers are responsible to stay informed with Microsoft vulnerability notifications and to visit the Invasive

Cardiology websites to understand the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi impact. Once a security patch is

validated, customers are responsible for the installation of security patches. All Mac-Lab IT/XT/XTi and CardioLab

IT/XT/XTi Security Patch Installation Instructions are available on the Invasive Cardiology Security Website below the

Validated Patches table.

Vulnerabilities exposed after the Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi product release which do not meet the

criteria to be validated are not listed within the GEHC Product Security Database and Invasive Cardiology Security

Website. These vulnerabilities are deemed to be non-critical and/or outside normal clinical workflow of the Mac-Lab

Page 2: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 2 of 65 GE Healthcare/September 18, 2014

IT/XT/XTi, CardioLab IT/XT/XTi and Centricity INW systems and will not be validated. Unlisted patches should not be

installed on the products in order to eliminate malfunction and breakdown risks.

Page 3: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 3 of 65 GE Healthcare/September 18, 2014

CONTENTS Validated Patches ..................................................................................................................................... 5

6.9.6 .............................................................................................................................................................................................................. 5

6.9.5 .............................................................................................................................................................................................................. 5

6.9 .................................................................................................................................................................................................................. 6

6.8.1 .............................................................................................................................................................................................................. 8

6.8 ................................................................................................................................................................................................................ 10

6.5.6 ............................................................................................................................................................................................................ 11

6.5.4 ............................................................................................................................................................................................................ 12

6.5.3 ............................................................................................................................................................................................................ 13

Installation of the Security Patches on MLCL systems .................................................................... 14

Requirements: ........................................................................................................................................................................................ 14

How to Install Printer firmware ..................................................................................................................................................... 14

How to logon Acquisition and Review Systems .................................................................................................................... 14

How to log on Centricity Cardiology INW Server .................................................................................................................. 15

How to log on MLCL Software Only Systems .................................................................................................................... 15

Security Patch Links ............................................................................................................................... 16

MLCL v6.9.6 ............................................................................................................................................................................................. 16

MLCL v6.9.5 ............................................................................................................................................................................................. 16

MLCL v6.9.5 Firmware........................................................................................................................................................................ 17

MLCL v6.9 ................................................................................................................................................................................................. 18

MLCL v6.9 Firmware ........................................................................................................................................................................... 19

MLCL v6.8.1 ............................................................................................................................................................................................. 20

MLCL v6.8 ................................................................................................................................................................................................. 26

MLCL v6.5.6 ............................................................................................................................................................................................. 28

MLCL v6.5.4 ............................................................................................................................................................................................. 31

MLCL v6.5.3 ............................................................................................................................................................................................. 35

DMS Security Patches ........................................................................................................................................................................ 38

Definition .................................................................................................................................................................................................. 43

Anti-Virus Installation for Mac-Lab\CardioLab\INW Server .......................................................... 45

Anti-Virus Requirements ................................................................................................................................................................... 45

Validated Anti-Virus Software ........................................................................................................................................................ 46

User Account Control ......................................................................................................................................................................... 46

Customer-Provided Server Configuration ................................................................................................................................ 46

Page 4: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 4 of 65 GE Healthcare/September 18, 2014

Anti-Virus Installation Instructions .............................................................................................................................................. 47

Symantec EndPoint Protection ...................................................................................................................................................... 47

McAfee VirusScan Enterprise ......................................................................................................................................................... 47

McAfee ePolicy Orchestrator .......................................................................................................................................................... 47

Trend Micro OfficeScan Client/Server Edition ........................................................................................................................ 47

Anti-Virus Software Common Installation Procedures ................................................................................................. 47

Symantec EndPoint Protection ...................................................................................................................................................... 49

Installation Overview..................................................................................................................................................................... 49

Pre-Installation Guidelines ......................................................................................................................................................... 49

Symantec EndPoint Protection Deployment Steps (Preferred Push Installation Method) ........................... 49

Symantec EndPoint Protection Server Console Configurations ............................................................................... 50

Symantec EndPoint Protection Post Installation Guidelines ...................................................................................... 52

McAfee VirusScan Enterprise ......................................................................................................................................................... 53

Installation Overview..................................................................................................................................................................... 53

McAfee VirusScan Enterprise Installation Procedure .................................................................................................... 53

McAfee VirusScan Enterprise Configuration ...................................................................................................................... 53

McAfee ePolicy Orchestrator .......................................................................................................................................................... 56

Installation Overview..................................................................................................................................................................... 56

Pre-Installation Guidelines ......................................................................................................................................................... 56

McAfee ePolicy Orchestrator Deployment Steps (Preferred Push Installation Method) ............................... 56

McAfee ePolicy Orchestrator Server Console Configuration ..................................................................................... 58

McAfee ePolicy Orchestrator Post Installation ................................................................................................................. 60

Trend Micro OfficeScan Client/Server Edition ........................................................................................................................ 61

Installation Overview..................................................................................................................................................................... 61

Pre-Installation Guidelines ......................................................................................................................................................... 61

Trend Micro OfficeScan Deployment Steps (Preferred Push Installation Method) .......................................... 61

Trend Micro OfficeScan Server Console Configuration ................................................................................................ 62

Trend Micro OfficeScan Post Installation Guidelines ..................................................................................................... 64

Contact Information ............................................................................................................................... 65

Page 5: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 5 of 65 GE Healthcare/September 18, 2014

Validated Patches

Product and Version Number Vulnerable Operating System Validated Security Patches

6.9.6

Centricity Cardiology INW

Server version

MS09-043 KB947318,

MS11-049 KB2251487,

MS12-034 KB2596672,

MS13-081 KB2862330

Windows® 2008

R2 Server SP1

Mac-Lab IT/XT/XTi , CardioLab

IT/XT/XTi and SpecialsLab HP

Acq version

MS09-043 KB947318,

MS11-049 KB2251487,

MS12-034 KB2596672,

MS13-081 KB2862330

MS14-031 KB2957189

Windows® 7 SP1

32-bit

GE Client Review Workstation

version

MS11-049 KB2251487,

MS13-075 KB2687413,

MS13-081 KB2862330

MS14-031 KB2957189

Windows® 7 SP1

32-bit

6.9.5

Centricity Cardiology INW

Server version 6.9.5

MS14-031 KB2957189,

HPSBMU03051

Windows 2008

R2 Server SP1

MS13-001 KB2769369, MS13-018

KB2790655, MS13-049 KB2845690,

MS13-062 KB2849470, MS13-065

KB2868623, MS13-079 KB2853587

(Domain Controller only), MS13-081

KB2862330, MS13-081 KB2862335,

MS13-081 KB2864202, MS13-081

KB2868038, MS13-081 KB2884256,

MS14-016 KB2923392 (Domain

Controller only)

Mac-Lab IT/XT/XTi , CardioLab

IT/XT/XTi and SpecialsLab HP

Acq version 6.9.5

Windows XP SP3 MS13-062 KB2849470, MS13-081

KB2862330, MS13-081 KB2862335,

MS13-081 KB2868038, MS13-081

KB2884256

GE Client Review Workstation

version 6.9.5

Windows XP SP3 MS13-062 KB2849470, MS13-081

KB2862330, MS13-081 KB2862335,

MS13-081 KB2868038, MS13-081

KB2884256

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.9.5

Windows XP SP3

Windows XP SP3 MS13-062 KB2849470, MS13-081

KB2862330, MS13-081 KB2862335,

MS13-081 KB2868038, MS13-081

KB2884256

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.9.5

Windows 7 SP1

MS14-031 KB2957189

Windows 7 SP1

32-bit

MS13-001 KB2769369, MS13-018

KB2790655, MS13-049 KB2845690,

MS13-062 KB2849470, MS13-065

KB2868623, MS13-081 KB2862330,

MS13-081 KB2862335, MS13-081

Page 6: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 6 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

KB2864202, MS13-081 KB2868038,

MS13-081 KB2884256

HP Printers

HP CP2025N printer

HP LaserJet Pro 400

color Printer M451

HP LaserJet Pro 400

Printer M401

Pre-9/23/2013

Firmware

HPSBPI02938

6.9

Centricity Cardiology INW

Server version 6.9

MS13-001 KB2769369,

MS13-018 KB2790655,

MS14-031 KB2957189,

HPSBMU03051

Windows 2008

R2 Server SP1

Operating System:

MS11-058 KB2562485 (Domain

Controller only), MS11-063

KB2567680, MS11-064 KB2563894,

MS11-083 KB2588516, MS12-004

KB2631813, MS12-005 KB2584146,

MS12-017 KB2647170 (Domain

Controller only), MS12-020

KB2621440, MS12-020 KB2667402,

MS12-036 KB2685939, MS12-054

KB2705219, MS12-054 KB2712808

Mac-Lab IT/XT/XTi , CardioLab

IT/XT/XTi and SpecialsLab HP

Acq version 6.9

MS13-062 KB2849470,

MS13-081 KB2862330,

MS13-081 KB2862335,

MS13-081 KB2868038,

MS13-081 KB2884256

Windows XP SP3 Operating System:

MS11-062 KB2566454, MS11-063

KB2567680, MS11-065 KB2570222,

MS12-004 KB2631813, MS12-004

KB2598479, MS12-005 KB2584146,

MS12-020 KB2621440, MS12-036

KB2685939, MS12-053 KB2723135,

MS12-054 KB2705219, MS12-054

KB2712808

MS11-062 KB2566454,

MS11-063 KB2567680,

MS11-065 KB2570222,

MS12-004 KB2598479,

MS12-004 KB2631813,

MS12-020 KB2621440,

MS12-036 KB2685939,

MS12-053 KB2723135,

MS12-054 KB2705219,

MS12-054 KB2712808

GE Client Review Workstation

version 6.9

MS13-062 KB2849470,

MS13-081 KB2862330,

MS13-081 KB2862335,

MS13-081 KB2868038,

MS13-081 KB2884256

Windows XP SP3 Operating System:

MS11-062 KB2566454, MS11-063

KB2567680, MS11-065 KB2570222,

MS12-004 KB2631813, MS12-004

KB2598479, MS12-005 KB2584146,

MS12-020 KB2621440, MS12-036

KB2685939, MS12-053 KB2723135,

MS12-054 KB2705219, MS12-054

Page 7: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 7 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

KB2712808, MS11-062 KB2566454

MS11-063 KB2567680,

MS11-065 KB2570222,

MS12-004 KB2598479,

MS12-004 KB2631813,

MS12-020 KB2621440,

MS12-036 KB2685939,

MS12-053 KB2723135,

MS12-054 KB2705219,

MS12-054 KB2712808

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.9

Windows XP SP3

MS13-062 KB2849470,

MS13-081 KB2862330,

MS13-081 KB2862335,

MS13-081 KB2868038,

MS13-081 KB2884256

Windows XP SP3 Operating System:

MS11-062 KB2566454, MS11-063

KB2567680, MS11-065 KB2570222,

MS12-004 KB2631813, MS12-004

KB2598479, MS12-005 KB2584146,

MS12-020 KB2621440, MS12-036

KB2685939, MS12-053 KB2723135,

MS12-054 KB2705219, MS12-054

KB2712808,

MS11-062 KB2566454,

MS11-063 KB2567680,

MS11-065 KB2570222,

MS12-004 KB2598479,

MS12-004 KB2631813,

MS12-020 KB2621440,

MS12-036 KB2685939,

MS12-053 KB2723135,

MS12-054 KB2705219,

MS12-054 KB2712808

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.9

Windows 7 SP1

MS13-001 KB2769369,

MS13-018 KB2790655,

MS13-049 KB2845690,

MS13-062 KB2849470,

MS13-065 KB2868623,

MS13-081 KB2862330,

MS13-081 KB2862335,

MS13-081 KB2864202,

MS13-081 KB2868038,

MS13-081 KB2884256,

MS14-031 KB2957189

Windows 7 SP1

32-bit

Operating System:

MS11-063 KB2567680, MS11-064

KB2563894, MS11-083 KB2588516,

MS12-004 KB2631813, MS12-005

KB2584146, MS12-020 KB2621440,

MS12-020 KB2667402, MS12-036

KB2685939, MS12-054 KB2705219,

MS12-054 KB2712808,

MS11-063 KB2567680,

MS11-064 KB2563894,

MS11-083 KB2588516,

MS12-004 KB2631813,

MS12-020 KB2621440,

MS12-020 KB2667402,

MS12-036 KB2685939,

MS12-054 KB2705219,

MS12-054 KB2712808

HP Printers

HP CP2025N printer

HP LaserJet Pro 400

Pre-9/23/2013

Firmware

HPSBPI02938

Page 8: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 8 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

color Printer M451

HP LaserJet Pro 400

Printer M401

6.8.1

Centricity Cardiology INW

Server version 6.8.1

Windows 2003

Server SP2

Operating System:

MS09-066 (Domain Controller only)

KB973039, MS09-073 KB973904,

MS10-046 KB2286198, MS10-054

KB982214, MS10-061 KB2347290,

MS11-019 KB2511455, MS11-020

KB2508429, MS11-058 (Domain

Controller only) KB2562485, MS11-

065 KB2570222, MS12-004

KB2631813, MS12-004 KB2598479,

MS12-005 KB2584146, MS12-017

(Domain Controller only) KB2647170,

MS12-020 KB2621440, MS12-036

KB2685939, MS12-054 KB2705219,

MS12-054 KB2712808

Mac-Lab IT/XT/XTi , CardioLab

IT/XT/XTi and SpecialsLab HP

Acq version 6.8.1

Windows XP SP3 Operating System:

MS09-073 KB973904, MS10-046

KB2286198, MS10-054 KB982214,

MS10-061 KB2347290, MS11-019

KB2511455, MS11-020 KB2508429,

MS11-065 KB2570222, MS12-004

KB2631813, MS12-004 KB2598479,

MS12-005 KB2584146, MS12-020

KB2621440, MS12-036 KB2685939,

MS12-053 KB2723135, MS12-054

KB2705219, MS12-054 KB2712808,

MS12-082 KB2770660

Microsoft Office 2007 with SP2:

MS09-062 KB972581, MS10-017

KB978382, MS10-031 KB976321,

MS10-105 KB2288931, MS11-023

KB2509488, MS11-036

KB2535818, MS11-045 KB2541007,

MS11-072 KB2553073,MS11-073

KB2584063, MS11-089 KB2596785,

MS12-027 KB2598041, MS12-030

KB2597969, MS12-030 KB2597161,

MS12-034 KB2596792, MS12-034

KB2596672, MS12-057 KB2596754,

MS12-057 KB2596615, MS12-060

KB2687441, MS12-076 KB2687307

GE Client Review Workstation

version 6.8.1

Windows XP SP3 Operating System:

MS09-073 KB973904, MS10-046

Page 9: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 9 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

KB2286198, MS10-054 KB982214,

MS10-061 KB2347290, MS11-019

KB2511455, MS11-020 KB2508429,

MS11-065 KB2570222, MS12-004

KB2631813, MS12-004 KB2598479,

MS12-005 KB2584146, MS12-020

KB2621440, MS12-036 KB2685939,

MS12-053 KB2723135, MS12-054

KB2705219, MS12-054 KB2712808,

MS12-082 KB2770660

Microsoft Office 2007 with SP2:

MS09-062 KB972581, MS10-017

KB978382, MS10-031 KB976321,

MS10-105 KB2288931, MS11-023

KB2509488, MS11-036

KB2535818, MS11-045 KB2541007,

MS11-072 KB2553073, MS11-073

KB2584063, MS11-089 KB2596785,

MS12-027 KB2598041, MS12-030

KB2597969, MS12-030 KB2597161,

MS12-034 KB2596792, MS12-034

KB2596672, MS12-057 KB2596754,

MS12-057 KB2596615, MS12-060

KB2687441, MS12-076 KB2687307

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.8.1

Windows XP SP3

Windows XP SP3 Operating System:

MS09-032 KB973346, MS09-034 IE6

KB972260, MS09-037 KB973354,

MS09-037 KB973540, MS09-037

KB973507, MS09-037 KB973869,

MS09-037 KB973815,

MS09-065 KB969947, MS09-073

KB973904, MS10-012 KB971468,

MS10-046 KB2286198, MS10-054

KB982214, MS10-061 KB2347290,

MS11-019 KB2511455, MS11-020

KB2508429, MS11-065 KB2570222,

MS12-004 KB2631813, MS12-004

KB2598479, MS12-005 KB2584146,

MS12-020 KB2621440, MS12-036

KB2685939, MS12-053 KB2723135,

MS12-054 KB2705219, MS12-054

KB2712808, MS12-082 KB2770660

Microsoft Office 2007:

Office Language Pack 2007 SP3,

MS09-062 KB972581(MS Office 2007

SP1/SP2), MS11-089 KB2596785,

MS12-027 KB2598041, MS12-030

Page 10: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 10 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

KB2597969, MS12-030 KB2597161,

MS12-034 KB2596792, MS12-034

KB2596672, MS12-057 KB2596754,

MS12-057 KB2596615, MS12-060

KB2687441, MS12-076 KB2687307,

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.8.1

Windows Vista

Business SP2

Windows Vista

Business SP2

Operating System:

MS09-034 IE7\IE8 KB972260, MS09-

037 KB973540, MS09-037 KB973507

MS09-048 KB967723, MS09-050

KB975517, MS09-065 KB969947,

MS10-012 KB971468, MS10-046

KB2286198, MS10-054 KB982214,

MS10-061 KB2347290, MS11-019

KB2511455, MS11-020 KB2508429,

MS11-030 KB2509553, MS11-048

KB2536275, MS11-064 KB2563894,

MS11-083 KB2588516, MS12-004

KB2631813, MS12-004 KB2598479,

MS12-005 KB2584146, MS12-020

KB2621440, MS12-036 KB2685939,

MS12-054 KB2705219, MS12-054

KB2712808, MS12-082 KB2770660

Microsoft Office 2007:

Office Language Pack 2007 SP3,

MS11-089 KB2596785, MS12-027

KB2598041, MS12-030 KB2597969,

MS12-030 KB2597161, MS12-034

KB2596792, MS12-034 KB2596672,

MS12-057 KB2596754, MS12-057

KB2596615, MS12-060 KB2687441,

MS12-076 KB2687307

HP Printers

HP CP2025N printer

HP LaserJet Pro 400

color Printer M451

HP LaserJet Pro 400

Printer M401

Pre-9/23/2013

Firmware

6.8

Centricity Cardiology INW

Server version 6.8

Windows 2003

Server SP2

MS09-018 KB969805 (Domain

Controller only)

MS09-032, MS09-034 IE6

MS09-037 KB973354

MS09-037 KB973540

MS09-037 KB973507

MS09-037 KB973869

MS09-037 KB973815

MS09-048, MS09-065, MS10-012

Page 11: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 11 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

MS10-046, MS10-054, MS10-061

MS11-019, MS11-020

Mac-Lab IT/XT/XTi , CardioLab

IT/XT/XTi and SpecialsLab HP

Acq/Review version 6.8

Windows XP SP3 MS09-032, MS09-034 IE6

MS09-037 KB973354

MS09-037 KB973540

MS09-037 KB973507

MS09-037 KB973869

MS09-037 KB973815

MS09-065, MS10-012, MS10-046

MS10-054, MS10-061, MS11-019

MS11-020

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.8

Windows XP SP3

Windows XP SP3 MS09-032, MS09-034 IE6

MS09-037 KB973354

MS09-037 KB973540

MS09-037 KB973507

MS09-037 KB973869

MS09-037 KB973815

MS09-065, MS10-012, MS10-046

MS10-054, MS10-061, MS11-019

MS11-020

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.8

Windows Vista

Business SP1

Windows Vista

Business SP1

MS09-034 IE7, IE8

MS09-037 KB973540

MS09-037 KB973507

MS09-048, MS09-050, MS09-065

MS10-012, MS10-046, MS10-054

MS10-061, MS11-019, MS11-020

MS11-030

HP Printers

HP CP2025N printer

HP LaserJet Pro 400

color Printer M451

HP LaserJet Pro 400

Printer M401

Pre-9/23/2013

Firmware

6.5.6

Centricity Cardiology INW

Server version 6.5.6

Windows 2003

Server SP2

MS10-046, MS10-054, MS10-061

MS11-019, MS11-020

Mac-Lab IT/XT/XTi , CardioLab

IT/XT/XTi and SpecialsLab HP

Acq/Review version 6.5.6

Windows XP SP3 MS10-046, MS10-054, MS10-061

MS11-019, MS11-020

GE Client Review Workstation

version 6.5.6

Windows XP SP3 MS10-046, MS10-054, MS10-061

MS11-019, MS11-020

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.5.6

Windows XP SP3 MS09-032, MS09-034 IE6

MS09-037 KB973354

MS09-037 KB973540

Page 12: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 12 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

Windows XP SP3 MS09-037 KB973507

MS09-037 KB973869

MS09-037 KB973815

MS09-065, MS10-012, MS10-046

MS10-054, MS10-061, MS11-019

MS11-020

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.5.6

Windows Vista

Business SP2

Windows Vista

Business SP2

MS09-034 IE7, IE8

MS09-037 KB973540

MS09-037 KB973507

MS09-048, MS09-050, MS09-065

MS10-012, MS10-046, MS10-054

MS10-061, MS11-019, MS11-020

MS11-030

HP Printers

HP CP2025N printer

HP LaserJet Pro 400

color Printer M451

HP LaserJet Pro 400

Printer M401

Pre-9/23/2013

Firmware

6.5.4

Centricity Cardiology INW

Server version 6.5.4

Windows 2003

Server SP2

MS07-029 (Domain Controller only)

MS07-058, MS08-001, MS08-037

MS08-067, MS09-001

MS09-008 KB961063 (Domain

Controller only)

MS09-018 KB969805 (Domain

Controller only)

MS09-032, MS09-034 IE6

MS09-037 KB973815

MS09-037 KB973869

MS09-037 KB973507

MS09-037 KB973540 Media Player

10

MS09-037 KB973354 Outlook

Express 6

MS09-048, MS09-065, MS10-012

MS10-046, MS10-054, MS10-061

Mac-Lab IT/CardioLab IT HP

Acq/Review version 6.5.4

Windows XP SP2 MS07-058, MS08-001, MS08-037

MS08-067, MS09-001, MS09-032

MS09-034 IE6

MS09-037 KB973815

MS09-037 KB973869

MS09-037 KB973507

MS09-037 KB973540 Media Player 9

MS09-037 KB973354 Outlook

Page 13: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 13 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

Express 6

MS09-065, MS10-012

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.5.4

Windows XP SP2

Windows XP SP2 MS07-058, MS08-001, MS08-037

MS08-067, MS09-001, MS09-032

MS09-034 IE6, 7 and 8

MS09-037 KB973815

MS09-037 KB973869

MS09-037 KB973507

MS09-037 KB973540 Media Player 9,

10 and 11

MS09-037 KB973354 Outlook

Express 6

MS09-065, MS10-012

-In addition to the base

configuration.

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.5.4

Windows 2000 SP4

Windows 2000 SP4 MS06-070, MS08-001, MS08-037

MS08-067, MS09-001, MS09-022

MS09-034 IE5.01 and 6

MS09-037 KB973869

MS09-037 KB973507

MS09-037 KB973540 Media Player 9

MS09-037 KB973354 Outlook Express

5.5 SP2 and 6

MS09-065, MS10-012

6.5.3

Centricity Cardiology INW

Server version 6.5.3

Windows 2003

Server SP1

MS07-029 (Domain Controller only)

MS07-058, MS08-001, MS08-037

MS08-067, MS09-001

MS09-008 KB961063 (Domain

Controller only)

Mac-Lab IT/CardioLab IT HP

Acq/Review version 6.5.3

Windows XP SP2 MS07-058, MS08-001, MS08-037

MS08-067, MS09-001, MS09-032

MS09-034 IE6

MS09-037 KB973815

MS09-037 KB973869

MS09-037 KB973507

MS09-037 KB973540 Media Player 9

MS09-037 KB973354 Outlook

Express 6

MS09-065, MS10-012

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.5.3

Windows XP SP2

Windows XP SP2 MS06-035, MS06-036, MS06-040

MS07-058, MS08-001, MS08-037

MS08-067, MS09-001, MS09-032

MS09-034 IE6, 7 and 8

MS09-037 KB973815

MS09-037 KB973869

MS09-037 KB973507

Page 14: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 14 of 65 GE Healthcare/September 18, 2014

Product and Version Number Vulnerable Operating System Validated Security Patches

MS09-037 KB973540 Media Player 9,

10 and 11

MS09-037 KB973354 Outlook

Express 6

MS09-065, MS10-012

–In addition to the base

configuration.

Mac-Lab IT/CardioLab IT

Software Only Review

Workstation version 6.5.3

Windows 2000 SP4

Windows 2000 SP4 MS06-070, MS08-001, MS08-037

MS08-067, MS09-001, MS09-022

MS09-034 IE5.01 and 6

MS09-037 KB973869

MS09-037 KB973507

MS09-037 KB973540 Media Player 9

MS09-037 KB973354 Outlook

Express 5.5 SP2 and 6

MS09-065, MS10-012

–In addition to the base

configuration.

Installation of the Security Patches on MLCL systems

Requirements:

Updates may be applied at any time other than while the Mac-Lab IT/XT/XTi, CardioLab IT/XT/XTi or

SpecialsLab application is open.

Updates must be re-applied if the system is re-imaged.

Updates apply to both networked and standalone systems.

Best practice is to update all applicable MLCL systems at the site.

If any Mac-Lab IT/CardioLab IT system has a DMS or Carddas client, use the Mac-Lab IT/XT/XTi, CardioLab

IT/XT/XTi or SpecialsLab instructions.

How to Install Printer firmware

The system which will apply the firmware to the printer should be provided by the customer.

NOTE: Mac-Lab CardioLab system should not be used to download and/or apply the Printer Firmware.

Follow the download link in the table

Select the appropriate printer

Select English and the applicable MLCL operating system

Select English and under the Firmware category select the applicable Firmware Update Utility and Click

Download

Launch the firmware installer and follow the instructions to complete the firmware update

How to logon Acquisition and Review Systems

When starting up an Mac-Lab, CardioLab or SpecialsLab Acquisition or Review system, an auto-logon sequence

starts and automatically logs on to the operating system. To install a security patch, the user must be logged on as

mlcltechuser.

Page 15: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 15 of 65 GE Healthcare/September 18, 2014

NOTE: Password information is contained within the Security Guide Manual. Otherwise, contact the system administrator or GE Technical Support for current password information.

1. Power on the Acquisition system. 2. The system boots up to the Custom Shell screen.

3. Press Ctrl + Action + Del.

4. Click Logoff. On Windows XP, click Logoff again.

5. Click OK.

6. Immediately hold down the Shift key until the login window is displayed.

7. Log on to the operating system locally as mlcltechuser.

8. Log on to the Custom Shell locally as mlcltechuser.

How to log on Centricity Cardiology INW Server

Password information is contained within the Security Guide Manual. Otherwise, contact the system administrator

or GE Technical Support for current password information. Logon to the INW Server as administrator

How to log on MLCL Software Only Systems

Since Software Only systems are supported by the customer, the system needs to be logged into with an

administrator account.

Page 16: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 16 of 65 GE Healthcare/September 18, 2014

Security Patch Links

MLCL v6.9.6

Operating System Platform Windows Server 2008 R2 Windows 7 SP1

MLCL Hardware System INW Server GE Hardware Acq\Review

Security Patch

Current in released product Current in released product

MLCL v6.9.5

Operating

System

Platform

Windows Server 2008

R2 SP1

Windows XP SP3 Windows XP SP3 Windows 7 SP1

MLCL Hardware

System

INW Server GE Hardware

Acq\Review

Software Only System Software Only System

Security Patch

MS13-001

KB2769369

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=36336

N/A N/A http://www.microsoft.c

om/en-

in/download/details.asp

x?id=36274

MS13-018

KB2790655

http://www.microsoft .co

m/en-

in/download/details.asp

x?id=36651

N/A N/A http://www.microsoft.c

om/en-

in/download/details.asp

x?id=36694

MS13-049

KB2845690

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=39221

N/A N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=39217

MS13-062

KB2849470

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=39899

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=39825

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=39825

http://www.microsoft.c

om/en-

us/download/details.as

px?id=39890

MS13-065

KB2868623

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=39885

N/A N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=39809

MS13-079

KB2853587

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=40025

N/A N/A N/A

MS13-081

KB2862330

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=40372

http://www.microsoft.c

om/en-

us/download/details.as

px?id=40474

http://www.microsoft.c

om/en-

us/download/details.as

px?id=40474

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=40507

MS13-081

KB2862335

http://www.microsoft.co

m/en-

http://www.microsoft.c

om/en-

http://www.microsoft.c

om/en-

http://www.microsoft.c

om/en-

Page 17: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 17 of 65 GE Healthcare/September 18, 2014

in/download/details.asp

x?id=40590 us/download/details.as

px?id=40426 us/download/details.as

px?id=40426 in/download/details.asp

x?id=40409

MS13-081

KB2868038

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=40526

http://www.microsoft.c

om/en-

us/download/details.as

px?id=40497

http://www.microsoft.c

om/en-

us/download/details.as

px?id=40497

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=40395

MS13-081

KB2884256

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=40379

http://www.microsoft.c

om/en-

us/download/details.as

px?id=40438

http://www.microsoft.c

om/en-

us/download/details.as

px?id=40438

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=40407

MS13-081

KB2864202

http://www.microsoft.co

m/en-

in/download/details.asp

x?id=40404

N/A N/A http://www.microsoft.c

om/en-

in/download/details.asp

x?id=40601

MS14-016

KB2923392

http://www.microsoft .co

m/en-

us/download/details.asp

x?id=42099

N/A N/A N/A

MLCL v6.9.5 Firmware

HPSBPI02938 Pre-9/23/2013

Firmware

•HP CP2025N printer

http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?s

pf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-

navigationalState%3DdocId%253Demr_na-c04041432-

2%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vig

nette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

HPSBPI02938 Pre-9/23/2013

Firmware

•HP LaserJet Pro 400 Printer

M401

http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?s

pf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-

navigationalState%3DdocId%253Demr_na-c04041432-

2%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vig

nette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

HPSBPI02938 Pre-9/23/2013

Firmware

•HP LaserJet Pro 400 color

Printer M451

http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?s

pf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-

navigationalState%3DdocId%253Demr_na-c04041432-

2%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vig

nette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

HPSBPI02938 Pre-9/23/2013

Firmware

•HP LaserJet P2035N

N/A

HPSBPI02938 Pre-9/23/2013

Firmware

•HP LaserJet 2300

N/A

RICOH SP4100N

N/A

RICOH AP410N

N/A

RICOH CL3500N

N/A

RICOH CL3000 N/A

Page 18: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 18 of 65 GE Healthcare/September 18, 2014

MLCL v6.9

Operating

System

Platform

Windows Server 2008

R2 SP1

Windows XP SP3 Windows XP SP3 Windows 7 SP1

MLCL Hardware

System

INW Server GE Hardware

Acq\Review

Software Only System Software Only System

Security Patch

MS12-054

KB2705219

http://www.microsoft.co

m/en-

us/download/details.asp

x?id=30492

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30497

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30497

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30547

Ms12-054

KB2712808

http://www.microsoft.co

m/en-

us/download/details.asp

x?id=30555

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30529

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30529

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30535

MS12-053

KB2723135

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=30590

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30590

N/A

MS12-036

KB2685939

http://www.microsoft.com/en-us/download/details.aspx?id=30021

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30022

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30022

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30087

MS12-020

KB2621440

http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=29116

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=29125

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=29125

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=29132

MS12-020

KB2667402

http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=29169

N/A N/A http://www.microsoft.c

om/en-

us/download/details.as

px?displaylang=en&id=

29145

MS12-017

KB2647170

(Domain

Controller Only)

http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=29164

N/A N/A N/A

MS12-005

KB2584146

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=28620

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=28608

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=28608

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=28597

MS12-004

KB2598479

N/A http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28638

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28638

N/A

Page 19: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 19 of 65 GE Healthcare/September 18, 2014

MS12-004

KB2631813

http://www.microsoft.co

m/download/en/details.

aspx?displaylang=en&i

d=28617

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=28638

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=28638

http://www.microsoft.c

om/en-

us/download/details.as

px?displaylang=en&id

=28593

MS11-083

KB2588516

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27894

N/A N/A http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27902

MS11-065

KB2570222

N/A http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27056

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27056

N/A

MS11-064

KB2563894

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27074

N/A N/A http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27052

MS11-063

KB2567680

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27039

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27008

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27008

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27025

MS11-062

KB2566454

N/A www.microsoft.com/downloads/details.aspx?familyid=6BC1F0AC-223D-4B0B-86CD-2BA3863955C4

www.microsoft.com/downloads/details.aspx?familyid=6BC1F0AC-223D-4B0B-86CD-2BA3863955C4

N/A

MS11-058

KB2562485 (Domain

Controller only)

http://www.microsoft.com/en-us/download/details.aspx?id=27027

N/A N/A N/A

MLCL v6.9 Firmware

HPSBPI02938 Pre-9/23/2013

Firmware

•HP CP2025N printer

http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?s

pf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-

navigationalState%3DdocId%253Demr_na-c04041432-

2%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vig

nette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

HPSBPI02938 Pre-9/23/2013

Firmware

•HP LaserJet Pro 400 Printer

M401

http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?s

pf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-

navigationalState%3DdocId%253Demr_na-c04041432-

2%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vig

nette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

HPSBPI02938 Pre-9/23/2013

Firmware

•HP LaserJet Pro 400 color

Printer M451

http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?s

pf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-

navigationalState%3DdocId%253Demr_na-c04041432-

2%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vig

nette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

HPSBPI02938 Pre-9/23/2013

Firmware

N/A

Page 20: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 20 of 65 GE Healthcare/September 18, 2014

•HP LaserJet P2035N

HPSBPI02938 Pre-9/23/2013

Firmware

•HP LaserJet 2300

N/A

RICOH SP4100N

N/A

RICOH AP410N

N/A

RICOH CL3500N

N/A

RICOH CL3000

N/A

MLCL v6.8.1

Operating

System

Platform

Windows Server 2003

SP2

Windows XP SP3 Windows XP SP3 Windows Vista SP2

MLCL Hardware

System

INW Server GE Hardware

Acq\Review

Software Only System Software Only System

Security Patch

MS12-082

KB2770660

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=35872

http://www.microsoft.c

om/en-

us/download/details.as

px?id=35872

http://www.microsoft.c

om/en-

us/download/details.as

px?id=35867

MS12-076

KB2687307

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=35710

http://www.microsoft.c

om/en-

us/download/details.as

px?id=35710

http://www.microsoft.c

om/en-

us/download/details.as

px?id=35710

MS12-060

KB2687441

N/A http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30619

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30619

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30619

MS12-057

KB2596754

N/A http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30633

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30633

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30633

MS12-057

KB2596615

N/A http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30614

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30614

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=30614

MS12-054

KB2712808

http://www.microsoft.co

m/en-

us/download/details.asp

x?id=30518

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30529

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30529

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30552

Page 21: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 21 of 65 GE Healthcare/September 18, 2014

MS12-054

KB2705219

http://www.microsoft.co

m/en-

us/download/details.asp

x?id=30482

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30497

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30497

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30544

MS12-053

KB2723135

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=30590

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30590

N/A

MS12-036

KB2685939

http://www.microsoft.co

m/en-

us/download/details.asp

x?id=30018

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30022

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30022

http://www.microsoft.c

om/en-

us/download/details.as

px?id=30020

MS12-034

KB2596792

N/A www.microsoft.com/en

-

us/download/details.as

px?id=29753

www.microsoft.com/en

-

us/download/details.as

px?id=29753

www.microsoft.com/en

-

us/download/details.as

px?id=29753

MS12-034

KB2596672

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=29730

http://www.microsoft.c

om/en-

us/download/details.as

px?id=29730

http://www.microsoft.c

om/en-

us/download/details.as

px?id=29730

MS12-030

KB2597969

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=29772

http://www.microsoft.c

om/en-

us/download/details.as

px?id=29772

http://www.microsoft.c

om/en-

us/download/details.as

px?id=29772

MS12-030

KB2597161

N/A http://www.microsoft.c

om/en-

in/download/details.asp

x?id=29798

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=29798

http://www.microsoft.c

om/en-

in/download/details.asp

x?id=29798

MS12-027

KB2598041

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=29372

http://www.microsoft.c

om/en-

us/download/details.as

px?id=29372

http://www.microsoft.c

om/en-

us/download/details.as

px?id=29372

MS12-020

KB2621440

http://www.microsoft.co

m/download/en/details.

aspx?displaylang=en&id

=29134

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=29125

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=29125

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=29126

MS12-017

KB2647170

Domain

Controller Only

http://www.microsoft.co

m/download/en/details.

aspx?displaylang=en&id

=29147

N/A N/A N/A

MS12-005

KB2584146

http://www.microsoft.co

m/download/en/details.

aspx?displaylang=en&id

=28611

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28608

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28608

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28646

MS12-004

KB2631813

http://www.microsoft.co

m/download/en/details.

aspx?displaylang=en&id

=28687

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28669

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28669

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28640

Page 22: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 22 of 65 GE Healthcare/September 18, 2014

MS12-004

KB2598479

http://www.microsoft.co

m/download/en/details.

aspx?displaylang=en&id

=28621

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28638

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28638

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28605

MS11-089

KB2596785

N/A http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28512

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28512

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=28512

MS11-083

KB2588516

N/A N/A N/A http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=27893

MS11-073

KB2584063

N/A http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=27383

N/A N/A

MS11-072

KB2553073

N/A http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=27331

N/A N/A

MS11-065

KB2570222

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27024

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=27056

http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en&

id=27056

N/A

MS11-064

KB2563894

N/A N/A N/A http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=27089

MS11-058

KB2562485 (Domain

Controller only)

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27062

N/A N/A N/A

MS11-048

KB2536275

N/A N/A N/A http://www.microsoft.c

om/download/en/detail

s.aspx?displaylang=en

&id=26335

MS11-045

KB2541007

N/A http://www.microsoft.c

om/download/en/detail

s.aspx?id=26475

N/A N/A

MS11-036

KB2535818

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?displaylang=en&id

=24723

N/A N/A

Page 23: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 23 of 65 GE Healthcare/September 18, 2014

MS11-030

KB2509553

N/A N/A N/A http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=2A17E

44F-54AA-423D-B3C7-

A4F404F7C28B&display

lang=en

MS11-023

KB2509488

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=25060

N/A N/A

MS11-020

KB2508429

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=64C550D

4-C927-4382-91E1-

473ED6790819&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=CCB08

A8A-F4D9-4320-8FFB-

3FD4FE217987&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=CCB08

A8A-F4D9-4320-8FFB-

3FD4FE217987&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=D6ED

DFF4-A242-4DEC-

9D84-

72891DB2B754&display

lang=en

MS11-019

KB2511455

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=D46FE0BF

-28C2-4696-87BC-

DD3C8287FC28&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=F5378

E7B-4619-4C42-9D9F-

87B209C6D878&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=F5378

E7B-4619-4C42-9D9F-

87B209C6D878&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=DA8D

D55D-6630-484E-836C-

9FEEAB5CC311&display

lang=en

MS10-105

KB2288931

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=16698

N/A N/A

MS10-061

KB2347290

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=3D79680

B-C071-462F-9CEA-

551FBD42EDF0&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=93FAB

A6B-0A85-4ACC-B527-

A012BBF56B13&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=93FAB

A6B-0A85-4ACC-B527-

A012BBF56B13&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=02897

7FD-0F39-42D4-9FEE-

0D90A2931CFD&displa

ylang=en

MS10-054

KB982214

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=230E8559

-E6DF-49D5-ACB5-

B0CD4BDE0BF4&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=6E5E1

6F8-C140-4A1D-B898-

8417A6BFD4D8&displa

ylang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=6E5E1

6F8-C140-4A1D-B898-

8417A6BFD4D8&displa

ylang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=9087A

3AA-AA55-41F6-8C4C-

F322E4AA8681&display

lang=en

MS10-046

KB2286198

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=32FE91EF

-5A8D-4095-90EE-

2CA216696B09&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=32FE9

1EF-5A8D-4095-90EE-

2CA216696B09&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=32FE9

1EF-5A8D-4095-90EE-

2CA216696B09&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=52748

886-6280-4247-8CBD-

F64DB229EE66&display

lang=en

MS10-031

KB976321

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?id=6898

N/A N/A

Page 24: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 24 of 65 GE Healthcare/September 18, 2014

MS10-017

KB978382

N/A http://www.microsoft.c

om/en-

us/download/details.as

px?displaylang=en&id=

12462

N/A N/A

MS10-012

KB971468

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=16494da

c-553a-4de9-b751-

0d6b51cb43f0&displayl

ang=en

MS09-073

KB973904

http://www.microsoft.co

m/en-

us/download/details.asp

x?id=23444

http://www.microsoft.c

om/en-

us/download/details.as

px?id=4009

http://www.microsoft.c

om/en-

us/download/details.as

px?id=4009

N/A

MS09-066

KB973039

Domain

Controller Only

http://www.microsoft.co

m/download/en/details.

aspx?displaylang=en&id

=7440

N/A N/A N/A

MS09-065

KB969947

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=5456210

3-1d99-42d7-8f7f-

c0cbcdce90db&displayl

ang=en

MS09-062

KB972581

N/A http://www.microsoft.c

om/download/en/detail

s.aspx?id=6991

http://www.microsoft.c

om/download/en/detail

s.aspx?id=6991

N/A

MS09-050

KB975517

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=29842c0

c-8930-4b5f-83c6-

1a718974b63f&displayl

ang=en

MS09-048

KB967723

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=7d72f84

5-9feb-4685-a669-

f9d6ab54f9ed&displayl

ang=en

MS09-037

KB973815

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

N/A

Page 25: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 25 of 65 GE Healthcare/September 18, 2014

MS09-037

KB973507

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=80de158

d-157e-4c21-9154-

c1dbd6e57cb3&displayl

ang=en

MS09-037

KB973540

Media Player

10&11

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=ec84c98

b-6bc7-442f-9280-

d6e204280b2f&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=3766aed

9-93f5-478e-a5bf-

b7ee0b577088&displayl

ang=en

MS09-037

KB973540

Media Player 9

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=ec84c98

b-6bc7-442f-9280-

d6e204280b2f&displayl

ang=en

N/A

MS09-037

KB973354

Outlook

Express 6

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

N/A

MS09-034

KB972260 IE6

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

N/A

MS09-034

KB972260 IE7

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=c874c8f

8-0449-42b1-8d8b-

901040069568&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=d3be9a1

3-1a5b-4b74-9649-

449df923f573&displayl

ang=en

MS09-034

KB972260 IE8

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=0acc8aa

a-0ae1-412a-9f2b-

dc7c707cae00&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=b05a19f

7-7412-4c2b-ad11-

34396e54ca43&displayl

ang=en

MS09-032

KB973346

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

N/A

Page 26: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 26 of 65 GE Healthcare/September 18, 2014

MLCL v6.8

Operating

System

Platform

Windows Server 2003

SP2

Windows XP SP3 Windows XP SP3 Windows Vista SP1

MLCL Hardware

System

INW Server GE Hardware

Acq\Review

Software Only System Software Only System

Security Patch

MS11-030

KB2509553

N/A N/A N/A http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=2A17E

44F-54AA-423D-B3C7-

A4F404F7C28B&display

lang=en

MS11-020

KB2508429

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=64C550D

4-C927-4382-91E1-

473ED6790819&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=CCB08

A8A-F4D9-4320-8FFB-

3FD4FE217987&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=CCB08

A8A-F4D9-4320-8FFB-

3FD4FE217987&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=D6ED

DFF4-A242-4DEC-

9D84-

72891DB2B754&display

lang=en

MS11-019

KB2511455

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=D46FE0BF

-28C2-4696-87BC-

DD3C8287FC28&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=F5378

E7B-4619-4C42-9D9F-

87B209C6D878&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=F5378

E7B-4619-4C42-9D9F-

87B209C6D878&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=F5378

E7B-4619-4C42-9D9F-

87B209C6D878&display

lang=en

MS10-061

KB2347290

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=3D79680

B-C071-462F-9CEA-

551FBD42EDF0&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=93FAB

A6B-0A85-4ACC-B527-

A012BBF56B13&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=93FAB

A6B-0A85-4ACC-B527-

A012BBF56B13&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=02897

7FD-0F39-42D4-9FEE-

0D90A2931CFD&displa

ylang=en

MS10-054

KB982214

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=230E8559

-E6DF-49D5-ACB5-

B0CD4BDE0BF4&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=6E5E1

6F8-C140-4A1D-B898-

8417A6BFD4D8&displa

ylang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=6E5E1

6F8-C140-4A1D-B898-

8417A6BFD4D8&displa

ylang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=9087A

3AA-AA55-41F6-8C4C-

F322E4AA8681&display

lang=en

MS10-046

KB2286198

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=32FE91EF

-5A8D-4095-90EE-

2CA216696B09&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=12361

875-B453-45E8-852B-

90F2727894FD&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=12361

875-B453-45E8-852B-

90F2727894FD&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=52748

886-6280-4247-8CBD-

F64DB229EE66&display

lang=en

Page 27: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 27 of 65 GE Healthcare/September 18, 2014

MS10-012

KB971468

http://www.microsoft.co

m/downloads/details.as

px?familyid=3d18cbc4-

ac48-458c-8aa3-

90708fd854ff&displaylan

g=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=16494da

c-553a-4de9-b751-

0d6b51cb43f0&displayl

ang=en

MS09-065

KB969947

http://www.microsoft.co

m/downloads/details.as

px?familyid=16494dac-

553a-4de9-b751-

0d6b51cb43f0&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=5456210

3-1d99-42d7-8f7f-

c0cbcdce90db&displayl

ang=en

MS09-050

KB975517

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=29842c0

c-8930-4b5f-83c6-

1a718974b63f&displayl

ang=en

MS09-048

KB967723

http://www.microsoft.co

m/downloads/details.as

px?familyid=48d82036-

2fde-4bb0-a60e-

92eed83ddc3f&displayla

ng=en

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=7d72f84

5-9feb-4685-a669-

f9d6ab54f9ed&displayl

ang=en

MS09-037

KB973815

http://www.microsoft.co

m/downloads/details.as

px?familyid=301ad191-

8d3f-41d3-b41c-

e2e863893f73&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

N/A

MS09-037

KB973869

http://www.microsoft.co

m/downloads/details.as

px?familyid=bfc474c2-

e3c5-40df-85d4-

4ac666ff0561&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=bdfcd0c

3-7c18-4e63-91dd-

d8f82cd89592&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=bdfcd0c

3-7c18-4e63-91dd-

d8f82cd89592&displayl

ang=en

N/A

MS09-037

KB973507

http://www.microsoft.co

m/downloads/details.as

px?familyid=7d9369b5-

0c54-4c17-bc62-

fba0a7b4728c&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=80de158

d-157e-4c21-9154-

c1dbd6e57cb3&displayl

ang=en

MS09-037

KB973540

Media Player 10

& 11

http://www.microsoft.co

m/downloads/details.as

px?familyid=ab054890-

983b-4414-ad0a-

da1b2d2a4895&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=ec84c98

b-6bc7-442f-9280-

d6e204280b2f&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=ec84c98

b-6bc7-442f-9280-

d6e204280b2f&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=3766aed

9-93f5-478e-a5bf-

b7ee0b577088&displayl

ang=en

Page 28: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 28 of 65 GE Healthcare/September 18, 2014

MS09-037

KB973540

Media Player 9

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=ec84c98

b-6bc7-442f-9280-

d6e204280b2f&displayl

ang=en

N/A

MS09-037

KB973354

Outlook

Express 6

http://www.microsoft.co

m/downloads/details.as

px?familyid=3119ab1e-

6729-40a1-b28f-

0dab50502be6&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

N/A

MS09-034

KB972260 IE6

http://www.microsoft.co

m/downloads/details.as

px?familyid=44852619-

58ad-48f2-bc55-

e8e1c72b1ba9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

N/A

MS09-034

KB972260 IE7

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=c874c8f

8-0449-42b1-8d8b-

901040069568&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=d3be9a1

3-1a5b-4b74-9649-

449df923f573&displayl

ang=en

MS09-034

KB972260 IE8

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=0acc8aa

a-0ae1-412a-9f2b-

dc7c707cae00&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=b05a19f

7-7412-4c2b-ad11-

34396e54ca43&displayl

ang=en

MS09-032

KB973346

http://www.microsoft.co

m/downloads/details.as

px?FamilyID=24701af8-

b87e-4e85-9463-

f50755a1b6ad&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

N/A

MS09-018

KB969805

Domain

Controller Only

http://www.microsoft.co

m/downloads/details.as

px?familyid=d814ce65-

a193-4027-a6cd-

106d388830a6&displayl

ang=en

N/A N/A N/A

MLCL v6.5.6

Operating

System

Platform

Windows Server 2003

SP2

Windows XP SP3 Windows XP SP3 Windows Vista SP2

MLCL Hardware INW Server GE Hardware Software Only System Software Only System

Page 29: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 29 of 65 GE Healthcare/September 18, 2014

System Acq\Review

Security Patch

MS11-030

KB2509553

N/A N/A N/A http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=2A17E

44F-54AA-423D-B3C7-

A4F404F7C28B&display

lang=en

MS11-020

KB2508429

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=64C550D

4-C927-4382-91E1-

473ED6790819&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=CCB08

A8A-F4D9-4320-8FFB-

3FD4FE217987&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=CCB08

A8A-F4D9-4320-8FFB-

3FD4FE217987&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=D6ED

DFF4-A242-4DEC-

9D84-

72891DB2B754&display

lang=en

MS11-019

KB2511455

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=D46FE0BF

-28C2-4696-87BC-

DD3C8287FC28&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=F5378

E7B-4619-4C42-9D9F-

87B209C6D878&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=F5378

E7B-4619-4C42-9D9F-

87B209C6D878&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=DA8D

D55D-6630-484E-836C-

9FEEAB5CC311&display

lang=en

MS10-061

KB2347290

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=3D79680

B-C071-462F-9CEA-

551FBD42EDF0&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=93FAB

A6B-0A85-4ACC-B527-

A012BBF56B13&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=93FAB

A6B-0A85-4ACC-B527-

A012BBF56B13&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=02897

7FD-0F39-42D4-9FEE-

0D90A2931CFD&displa

ylang=en

MS10-054

KB982214

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=230E8559

-E6DF-49D5-ACB5-

B0CD4BDE0BF4&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=6E5E1

6F8-C140-4A1D-B898-

8417A6BFD4D8&displa

ylang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=6E5E1

6F8-C140-4A1D-B898-

8417A6BFD4D8&displa

ylang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=9087A

3AA-AA55-41F6-8C4C-

F322E4AA8681&display

lang=en

MS10-046

KB2286198

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=32FE91EF

-5A8D-4095-90EE-

2CA216696B09&displayl

ang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=32FE9

1EF-5A8D-4095-90EE-

2CA216696B09&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=32FE9

1EF-5A8D-4095-90EE-

2CA216696B09&display

lang=en

http://www.microsoft.c

om/downloads/en/deta

ils.aspx?familyid=52748

886-6280-4247-8CBD-

F64DB229EE66&display

lang=en

MS10-012

KB971468

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=16494da

c-553a-4de9-b751-

0d6b51cb43f0&displayl

ang=en

MS09-065

KB969947

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

http://www.microsoft.c

om/downloads/details.

aspx?familyid=5456210

3-1d99-42d7-8f7f-

c0cbcdce90db&displayl

Page 30: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 30 of 65 GE Healthcare/September 18, 2014

ang=en ang=en

MS09-050

KB975517

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=29842c0

c-8930-4b5f-83c6-

1a718974b63f&displayl

ang=en

MS09-048

KB967723

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=7d72f84

5-9feb-4685-a669-

f9d6ab54f9ed&displayl

ang=en

MS09-037

KB973815

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

N/A

MS09-037

KB973507

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=80de158

d-157e-4c21-9154-

c1dbd6e57cb3&displayl

ang=en

MS09-037

KB973540

Media Player 10

& 11

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=ec84c98

b-6bc7-442f-9280-

d6e204280b2f&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=3766aed

9-93f5-478e-a5bf-

b7ee0b577088&displayl

ang=en

MS09-037

KB973540

Media Player 9

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=ec84c98

b-6bc7-442f-9280-

d6e204280b2f&displayl

ang=en

N/A

MS09-037

KB973354

Outlook

Express 6

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

N/A

Page 31: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 31 of 65 GE Healthcare/September 18, 2014

MS09-034

KB972260 IE6

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

N/A

MS09-034

KB972260 IE7

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=c874c8f

8-0449-42b1-8d8b-

901040069568&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=d3be9a1

3-1a5b-4b74-9649-

449df923f573&displayl

ang=en

MS09-034

KB972260 IE8

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=0acc8aa

a-0ae1-412a-9f2b-

dc7c707cae00&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=b05a19f

7-7412-4c2b-ad11-

34396e54ca43&displayl

ang=en

MS09-032

KB973346

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

N/A

MLCL v6.5.4

MLCL

Operating

System

Platform

Windows Server 2003

SP2

Windows XP SP2 Windows XP SP2 Windows 2000 SP4

MLCL Hardware

System

INW Server GE Hardware

Acq\Review

Software Only System Software Only System

Security Patch

MS10-061

KB2347290

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=3D79680

B-C071-462F-9CEA-

551FBD42EDF0&displayl

ang=en

N/A N/A N/A

MS10-054

KB982214

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=230E8559

-E6DF-49D5-ACB5-

B0CD4BDE0BF4&displayl

ang=en

N/A N/A N/A

Page 32: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 32 of 65 GE Healthcare/September 18, 2014

MS10-046

KB2286198

http://www.microsoft.co

m/downloads/en/details.

aspx?familyid=32FE91EF

-5A8D-4095-90EE-

2CA216696B09&displayl

ang=en

N/A N/A N/A

MS10-012

KB971468

http://www.microsoft.co

m/downloads/details.as

px?familyid=3d18cbc4-

ac48-458c-8aa3-

90708fd854ff&displaylan

g=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=267ce98

2-54a0-418f-ad52-

e4963610f714&displayl

ang=en

MS09-065

KB969947

http://www.microsoft.co

m/downloads/details.as

px?familyid=5cd62750-

e269-44ae-8c7c-

c335e8545b9a&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=45db8bb

1-c81b-4d3f-a658-

74f5fa445f81&displayla

ng=en

MS09-048

KB967723

http://www.microsoft.co

m/downloads/details.as

px?familyid=48d82036-

2fde-4bb0-a60e-

92eed83ddc3f&displayla

ng=en

N/A N/A N/A

MS09-037

KB973815

http://www.microsoft.co

m/downloads/details.as

px?familyid=301ad191-

8d3f-41d3-b41c-

e2e863893f73&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

N/A

MS09-037

KB973869

http://www.microsoft.co

m/downloads/details.as

px?familyid=bfc474c2-

e3c5-40df-85d4-

4ac666ff0561&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=bdfcd0c

3-7c18-4e63-91dd-

d8f82cd89592&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=bdfcd0c

3-7c18-4e63-91dd-

d8f82cd89592&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=223e25d

2-83d7-4cb7-85c4-

46a42b8110e0&displayl

ang=en

MS09-037

KB973507

http://www.microsoft.co

m/downloads/details.as

px?familyid=7d9369b5-

0c54-4c17-bc62-

fba0a7b4728c&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=c773149

a-f4fc-486a-b718-

6b8ff7a36ae2&displayl

ang=en

MS09-037

KB973540

Media Player 9,

10 & 11

http://www.microsoft.co

m/downloads/details.as

px?familyid=ab054890-

983b-4414-ad0a-

da1b2d2a4895&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=34b2b14

d-5811-4635-ba83-

f837dcb03d04

http://www.microsoft.c

om/downloads/details.

aspx?familyid=34b2b14

d-5811-4635-ba83-

f837dcb03d04

http://www.microsoft.c

om/downloads/details.

aspx?familyid=bd7c9fc

4-61cb-4c23-9961-

6d63f234731c&displayl

ang=en

Page 33: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 33 of 65 GE Healthcare/September 18, 2014

MS09-037

KB973354

Outlook

Express 6

http://www.microsoft.co

m/downloads/details.as

px?familyid=3119ab1e-

6729-40a1-b28f-

0dab50502be6&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

N/A

MS09-037

KB973354

Outlook

Express 5.5

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=6f9fcbe9

-8496-4d23-8a16-

b334157688c2&displayl

ang=en

MS09-034

KB972260

IE5.01

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=50ffc8f4

-7ab7-4e64-9965-

5767db5f53cd&displayl

ang=en

MS09-034

KB972260 IE6

http://www.microsoft.co

m/downloads/details.as

px?FamilyID=22bed634-

5227-4a22-8df5-

801f3e2e232a&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=93bd1b

aa-e2fb-4e8c-9dd7-

738efef32282&displayl

ang=en

MS09-034

KB972260 IE7

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=c874c8f

8-0449-42b1-8d8b-

901040069568

N/A

MS09-034

KB972260 IE8

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=0acc8aa

a-0ae1-412a-9f2b-

dc7c707cae00

N/A

MS09-032

KB973346

http://www.microsoft.co

m/downloads/details.as

px?FamilyID=b0a458d6-

c34c-41c7-964a-

c130cfcb0d01&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

N/A

MS09-022

KB961501

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=8637875

3-db24-44c2-a27d-

cc0239f40ab8&displayl

ang=en

Page 34: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 34 of 65 GE Healthcare/September 18, 2014

MS09-018

KB969805

Domain

Controller Only

http://www.microsoft.co

m/downloads/details.as

px?familyid=d814ce65-

a193-4027-a6cd-

106d388830a6&displayl

ang=en

N/A N/A N/A

MS09-008

KB961063

Domain

Controller Only

http://www.microsoft.co

m/downloads/details.as

px?familyid=6cc42c9e-

c34e-4577-8b23-

9e07e2369878&displayl

ang=en

N/A N/A N/A

MS09-001

KB958687

http://www.microsoft.co

m/downloads/details.as

px?familyid=588CA8E8-

38A9-47ED-9C41-

09AAF1022E49&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=EEAFCD

C5-DF39-4B29-B6F1-

7D32B64761E1&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=EEAFCD

C5-DF39-4B29-B6F1-

7D32B64761E1&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=E0678D1

4-C1B5-457A-8222-

8E7682760ED4&display

lang=en

MS08-067

KB958644

http://www.microsoft.co

m/downloads/details.as

px?familyid=F26D395D-

2459-4E40-8C92-

3DE1C52C390D&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=0D5F9B6

E-9265-44B9-A376-

2067B73D6A03&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=0D5F9B6

E-9265-44B9-A376-

2067B73D6A03&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=E22EB3A

E-1295-4FE2-9775-

6F43C5C2AED3&display

lang=en

MS08-037

KB951748

http://www.microsoft.co

m/downloads/details.as

px?familyid=4ef5033c-

9843-4e0b-bfad-

fcaf05d7dab9&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=ed989a3

3-7a9e-4423-93a8-

b38907467cdf&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=ed989a3

3-7a9e-4423-93a8-

b38907467cdf&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=269c219

c-9d6b-4b12-b621-

c70cd07cdd22&displayl

ang=en

MS08-037

KB951746

http://www.microsoft.co

m/downloads/details.as

px?familyid=d1fcb794-

e6a5-4c28-b3b3-

9cd88f468a42&displayla

ng=en

N/A N/A N/A

MS08-001

KB941644

http://www.microsoft.co

m/downloads/details.as

px?FamilyID=fda060a5-

9a1e-4036-9899-

13eb61fdd8be&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=0a7662

42-2342-4fa0-9b66-

8953c54a2211be&displ

aylang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=0a7662

42-2342-4fa0-9b66-

8953c54a2211be&displ

aylang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=980f545

7-c7b5-421c-8643-

0e57429ec159&displayl

ang=en

MS07-058

KB933729

http://www.microsoft.co

m/downloads/details.as

px?FamilyId=011593a0-

f37e-4578-bee1-

a985639b521b&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyId=1fee539

c-ab86-4298-b6f4-

22ce31ee7b8b&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyId=1fee539

c-ab86-4298-b6f4-

22ce31ee7b8b&displayl

ang=en

N/A

Page 35: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 35 of 65 GE Healthcare/September 18, 2014

MS07-029

KB935966

Domain

Controller Only

http://www.microsoft.co

m/downloads/details.as

px?FamilyId=dfb5eaca-

788b-475c-9817-

491f0b7cf295&displayla

ng=en

N/A N/A N/A

MS06-070

KB924270

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=3ad5c57

d-d3f6-46a1-8dee-

3e16d0977f80&displayl

ang=en

MLCL v6.5.3

Operating

System

Platform

Windows Server 2003

SP2

Windows XP SP2 Windows XP SP2 Windows 2000 SP4

MLCL Hardware

System

INW Server GE Hardware

Acq\Review

Software Only System Software Only System

Security Patch

MS10-012

KB971468

http://www.microsoft.co

m/downloads/details.as

px?familyid=3d18cbc4-

ac48-458c-8aa3-

90708fd854ff&displaylan

g=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8f7adee

3-e68e-41b3-b835-

d84691774f31&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=267ce98

2-54a0-418f-ad52-

e4963610f714&displayl

ang=en

MS09-065

KB969947

N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=916abda

d-44b7-4f9d-986a-

0c3558fb8e06&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=45db8bb

1-c81b-4d3f-a658-

74f5fa445f81&displayla

ng=en

MS09-037

KB973815

N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=8b71bcc

9-5146-4afc-8847-

0af21d7fad36&displayl

ang=en

N/A

MS09-037

KB973869

N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=bdfcd0c

3-7c18-4e63-91dd-

d8f82cd89592&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=bdfcd0c

3-7c18-4e63-91dd-

d8f82cd89592&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=223e25d

2-83d7-4cb7-85c4-

46a42b8110e0&displayl

ang=en

Page 36: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 36 of 65 GE Healthcare/September 18, 2014

MS09-037

KB973507

N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=4b4c6fc

5-e8e6-4d89-a181-

e231240468f9&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=c773149

a-f4fc-486a-b718-

6b8ff7a36ae2&displayl

ang=en

MS09-037

KB973540

Media Player 9,

10 & 11

N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=34b2b14

d-5811-4635-ba83-

f837dcb03d04

http://www.microsoft.c

om/downloads/details.

aspx?familyid=34b2b14

d-5811-4635-ba83-

f837dcb03d04

http://www.microsoft.c

om/downloads/details.

aspx?familyid=bd7c9fc

4-61cb-4c23-9961-

6d63f234731c&displayl

ang=en

MS09-037

KB973354

Outlook

Express 6

N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=c67b550

6-00ea-47cc-a0e8-

897057b7380c&displayl

ang=en

N/A

MS09-037

KB973354

Outlook

Express 5.5

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=6f9fcbe9

-8496-4d23-8a16-

b334157688c2&displayl

ang=en

MS09-034

KB972260

IE5.01

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=50ffc8f4

-7ab7-4e64-9965-

5767db5f53cd&displayl

ang=en

MS09-034

KB972260 IE6

N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=22bed6

34-5227-4a22-8df5-

801f3e2e232a&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=93bd1b

aa-e2fb-4e8c-9dd7-

738efef32282&displayl

ang=en

MS09-034

KB972260 IE7

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=c874c8f

8-0449-42b1-8d8b-

901040069568

N/A

MS09-034

KB972260 IE8

N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=0acc8aa

a-0ae1-412a-9f2b-

dc7c707cae00

N/A

Page 37: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 37 of 65 GE Healthcare/September 18, 2014

MS09-032

KB973346

N/A http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=24701af

8-b87e-4e85-9463-

f50755a1b6ad&displayl

ang=en

N/A

MS09-022

KB961501

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=8637875

3-db24-44c2-a27d-

cc0239f40ab8&displayl

ang=en

MS09-008

KB961063 (INW

DC)

http://www.microsoft.co

m/downloads/details.as

px?familyid=6cc42c9e-

c34e-4577-8b23-

9e07e2369878&displayl

ang=en

N/A N/A N/A

MS09-001

KB958687

http://www.microsoft.co

m/downloads/details.as

px?familyid=588CA8E8-

38A9-47ED-9C41-

09AAF1022E49&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=EEAFCD

C5-DF39-4B29-B6F1-

7D32B64761E1&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=EEAFCD

C5-DF39-4B29-B6F1-

7D32B64761E1&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=E0678D1

4-C1B5-457A-8222-

8E7682760ED4&display

lang=en

MS08-067

KB958644

http://www.microsoft.co

m/downloads/details.as

px?familyid=F26D395D-

2459-4E40-8C92-

3DE1C52C390D&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=0D5F9B6

E-9265-44B9-A376-

2067B73D6A03&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=0D5F9B6

E-9265-44B9-A376-

2067B73D6A03&display

lang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=E22EB3A

E-1295-4FE2-9775-

6F43C5C2AED3&display

lang=en

MS08-037

KB951748

http://www.microsoft.co

m/downloads/details.as

px?familyid=4ef5033c-

9843-4e0b-bfad-

fcaf05d7dab9&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=ed989a3

3-7a9e-4423-93a8-

b38907467cdf&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=ed989a3

3-7a9e-4423-93a8-

b38907467cdf&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?familyid=269c219

c-9d6b-4b12-b621-

c70cd07cdd22&displayl

ang=en

MS08-037

KB951746 (INW

DC)

http://www.microsoft.co

m/downloads/details.as

px?familyid=d1fcb794-

e6a5-4c28-b3b3-

9cd88f468a42&displayla

ng=en

N/A N/A N/A

MS08-001

KB941644

http://www.microsoft.co

m/downloads/details.as

px?FamilyID=fda060a5-

9a1e-4036-9899-

13eb61fdd8be&displayla

ng=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=0a7662

42-2342-4fa0-9b66-

8953c54a2211be&displ

aylang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=0a7662

42-2342-4fa0-9b66-

8953c54a2211be&displ

aylang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyID=980f545

7-c7b5-421c-8643-

0e57429ec159&displayl

ang=en

Page 38: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 38 of 65 GE Healthcare/September 18, 2014

MS07-058

KB933729

http://www.microsoft.co

m/downloads/details.as

px?FamilyId=011593a0-

f37e-4578-bee1-

a985639b521b&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyId=1fee539

c-ab86-4298-b6f4-

22ce31ee7b8b&displayl

ang=en

http://www.microsoft.c

om/downloads/details.

aspx?FamilyId=1fee539

c-ab86-4298-b6f4-

22ce31ee7b8b&displayl

ang=en

N/A

MS07-029

KB935966 (INW

DC)

http://www.microsoft.co

m/downloads/details.as

px?FamilyId=dfb5eaca-

788b-475c-9817-

491f0b7cf295&displayla

ng=en

N/A N/A N/A

MS06-070

KB924270

N/A N/A N/A http://www.microsoft.c

om/downloads/details.

aspx?familyid=3ad5c57

d-d3f6-46a1-8dee-

3e16d0977f80&displayl

ang=en

DMS Security Patches

Product and Version Number Vulnerable Operating

System

Validated Critical Security Patches

Centricity Cardiology DMS

Server (v. 2.x) (De-supported)

Windows

NT 4.0 SP6A

IE5.5 SP2

Centricity Cardiology DMS

Server (v. 2.x & 3.x) (De-

supported)

(3.x upgrades validated to

Oracle 8.1.7.4.13)

IE7.0 not

compatible

with

Cyberpulse

Windows

2000 Server

SP4 IE 5.5 SP2

Centricity Cardiology DMS

Admin, Interface and

Application Server (v. 4.0) (De-

supported)

Oracle

8.1.7.4.18 –

Failed to pass

IE7.0 not

compatible

with

Cyberpulse

Windows

2000 Server

SP4 IE 6.0 SP1

Centricity Cardiology DMS

Admin, Interface and

Application Server (v. 4.0x, 4.1.x,

4.2.x)

IE7.0 or IE8.0

not compatible

with

Cyberpulse,

MS10-061 - (KB2347290)

Windows

2003 Server

SP2 –

IE 6.0 SP1

MS07-012 (KB924667-v2), MS07-017 (KB925902) MS07-020 (KB932168), MS07-021 (KB930178) MS07-022 (KB931784), MS07-031 (KB935840) MS07-034(KB 929123), MS07-035 (KB935839), MS07-039(KB926122)MS07-040 (KB933854) MS07-042 (KB936021), MS07-047 (KB936782) MS07-050 (KB938127), MS07-056 (KB941202) MS07-058 (KB933729), MS07-061 (KB943460)

Page 39: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 39 of 65 GE Healthcare/September 18, 2014

MS07-064 (KB941568), MS08-001 (KB941644) MS08-002 (KB943485), MS08-005 (KB942831) MS08-006 (KB942830), MS08-008 (KB943055) MS08-010 (KB944533), MS08-036 (KB950762) MS08-049 (KB950974),MS08-066(KB956803) MS08-68(KB957097),MS08-076 (KB952069), MS09-010 (KB923561), MS09-012 (KB952004) MS09-012 (KB956572), MS09-013 (KB960803) MS09-015 (KB959426), MS09-020 (KB970483) MS09-028(KB971633), MS09-032(KB973346) MS09-034(KB972260) MS09-037 (KB973507), MS09-037 (KB973540) MS09-037 (KB973815), MS09-037 (KB973869) MS09-038(KB971557), MS09-040 (KB971032), MS09-041 (KB971657) MS09-042 (KB960859), MS09-044 (KB958469) MS09-046 (KB956844), MS09-048 (KB967723) MS09-051 (KB954155), MS09-051 (KB975025) MS09-052 (KB974112), MS09-056 (KB974571) MS09-057 (KB969059), MS09-059 (KB975467) MS09-069 (KB954430), MS09-069 (KB973688) MS09-069 (KB974392), MS09-071 (KB974318) MS09-073 (KB973904) MS10-001 (KB972270), MS10-005 (KB978706) MS10-007 (KB975713), MS10-013 (KB975560) MS10-013 (KB977914), MS10-019 (KB979309) MS10-020 (KB980232), MS10-026 (KB977816) MS10-029 (KB978338), MS10-030 (KB978542) MS10-033 (KB978695), MS10-033 (KB979482) MS10-041 (KB979907), MS10-042 (KB2229593) MS10-052 (KB2115168), MS10-062 (KB975558_WM8) MS10-063 (KB981322), MS10-065 (KB2124261) MS10-074 (KB2387149), MS10-076 (KB982132) MS10-081 (KB2296011), MS10-082 (KB2378111) MS10-083 (KB979687), MS10-084 (KB2360937) MS10-096 (KB2423089), MS10-097 (KB2443105) MS10-099 (KB2440591), MS11-002 (KB2419635) MS11-006 (KB2483185), MS11-011 (KB2393802) MS11-013 (KB2478971), MS11-014 (KB2478960) MS11-020 (KB2508429), MS11-024 (KB2491683) MS11-024 (KB2506212), MS11-030 (KB2509553) MS11-031 (KB2510587), MS11-032 (KB2507618) MS11-033 (KB2485663), MS11-037 (KB2544893-v2) MS11-038 (KB2476490), MS11-042 (KB2535512) MS11-043 (KB2536276-v2), MS11-052 (KB2544521) MS11-056 (KB2507938), MS11-066 (KB2487367) MS11-071 (KB2570947), MS11-075 (KB2564958) MS11-093 (KB2624667), MS11-090 (KB2618451) MS11-093 (KB2624667), MS11-097 (KB2620712) MS11-100 (KB2656358), MS11-100 (KB2656351) MS12-001 (KB2644615), MS12-002 (KB2603381) MS12-003 (KB2646524), MS12-004 (KB2598479) MS12-004 (KB2631813), MS12-005 (KB2584146) MS12-006 (KB2638806), MS12-009 (KB2645640) MS12-024 (KB2653956), MS12-025 (KB2656376-v2) MS12-034 (KB2659262), MS12-034 (KB2676562)

Page 40: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 40 of 65 GE Healthcare/September 18, 2014

MS12-034 (KB2686509), MS12-035 (KB2604078) MS12-035 (KB2604121), MS12-036 (KB2685939) MS12-043 (KB2719985), MS12-045 (KB2698365) MS12-048 (KB2691442), MS12-049 (KB2655992) MS12-054 (KB2705219-v2), MS12-054 (KB2712808) MS12-055 (KB2731847-v2), MS12-063 (KB2744842) MS12-068 (KB2724197), MS12-072 (KB2727528) MS12-074 (KB2729449), MS12-074 (KB2737019) MS12-078 (KB2748349), MS12-078 (KB2753842-v2) MS12-081 (KB2758857), MS12-082 (KB2770660) MS13-004 (KB2742595), MS13-004 (KB2742604) MS13-007 (KB2736428), MS13-011 (KB2780091) MS13-015 (KB2789642), MS13-027 (KB2807986) MS13-028 (KB2817183), MS13-031 (KB2813170) MS13-033 (KB2820917), MS13-036 (KB2808735) MS13-052(KB2833949), MS13-054(KB2834886), MS13-056(KB2845187), MS13-060(KB2850869), MS13-062 (KB2849470 ), MS13-063(KB2859537), MS13-070 (KB2876217),MS13-071(KB2864063) MS13-081(KB2847311), MS13-083 (KB2864058) MS13-088(KB2888505) MS13-089 (KB2876331), MS13-90(KB2900986), MS13-095(KB2868626), KB890830, KB982666KB2820917, KB927891 KB2345886, KB2489367KB2862152 KB2779562, KB2798897, KB2862330, KB2862335 KB3656351, KB2862772-IE8, KB2863058, KB2883150, KB2888505-IE8, KB924667-v2.,KB925902-v2., KB930178, KB931784, KB932168, KB3656351 Q147222, Q936181 Q954430, Q973688 SP1, KB2566454 KB2661254, KB2736233 KB2749655, KB2756822 KB914961, KB925398_WMP64 KB925902-v2, KB926122 KB927891, KB929123 KB931836, KB936357 KB941569, KB942763 KB942840, KB944653 KB946026, KB948496 KB952954, KB956802 KB956844, KB968389KB2779562 KB971029, KB973917-V2, KB2780091, KB2803821-v2, KB2807986, KB933729, KB933854, KB935839, KB935840, KB936021, KB936357, KB936357-v2., KB936782. KB938127, KB938464-v2. KB941202, KB941568,KB941569,KB941644, KB942763, KB942830, KB942831, KB943055. KB943460,KB943485,KB944338-v2.,KB944533, KB944653, KB945553, KB946026, KB948496. KB951066, KB951748, KB952069, KB952954. KB954155, KB954550-v5, KB954600, KB955069. KB955839, KB958469,KB958644, KB958687, KB960225,KB961118,KB961371-v2., KB961501,

Page 41: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 41 of 65 GE Healthcare/September 18, 2014

KB967715, KB967723, KB968537,KB970238, KB970430, KB970483, KB971029, KB971032, KB973354, KB973540, KB973825, KB973917-v2., KB978695,KB979907,KB980232,KB982381-IE8, KB982632-IE8, KB982666. KB925398_WMP64. KB2480118, KB2491683, KB2544521, KB2604078. KB2656376-v2. KB2661254 KB2744842, KB2753842-v2. KB2808735, KB2813170, KB2868038, KB925902. KB942840, KB914961,KB2736428,KB2742595 KB2789642,KB2835393,KB2840628,KB2858302 KB2861188,KB890830,KB2803821,KB2883150 KB2820197,KB2833949,KB2834886,KB2845187 KB2847311,KB2849470,KB2850869,KB2859537 KB2862152,KB2862330,KB2862335,KB2863058 KB2864058,KB2864063,KB2868038,KB2868626 KB2876217,KB2876331,KB2879017,KB2884256 KB2888505,KB2900986,KB954430,KB973688 KB2758696,KB2604092,KB2656352,KB2729450 KB2742596,KB2789643,KB2833940,KB2844285 KB2863239,KB982168,KB982524,KB2756918 KB2832411,KB2861189,KB2604111,KB2840629 KB2861697,KB2847367,KB2604121,KB2729449 KB2737019,KB961118,KB973904,KB982666 KB2345886 Q936181,Oracle 10.0.1.4, Oracle 10G patch 10.1.0.5.28, Oracle patch 10.1.0.5.32

Oracle Patch Rollup for 10.1.0.5 (P13413002)

Centricity Cardiology DMS Client

(v. 2.x) (De-supported)

Windows

NT 4.0 SP6A

IE5.5 SP2

Centricity Cardiology DMS Client

(v. 2.x & 3.x) (De-supported)

IE7.0 not

compatible

with

Cyberpulse

Windows

2000 SP4 IE

6.0 SP1

Centricity Cardiology DMS Client

(v. 4.0) (De-supported)

IE7.0 not

compatible

with

Cyberpulse

Windows

2000 SP4 IE

6.0 SP1

Centricity Cardiology DMS Client

(v. 4.0x, 4.1.x, 4.2.x)

Windows XP

SP3 –

IE 8.0

MS08-030(KB951376-v2),MS08-036(KB950762) MS08-046(KB952954),MS08-049(KB950974) MS08-050(KB946648),MS08-071(KB956802) MS08-076(KB952069_WM9), MS09-010(KB923561) MS09-012(KB952004),MS09-012(KB956572) MS09-013(KB960803),MS09-015(KB959426) MS09-037(KB973507),MS09-037(KB973815) MS09-037(KB973869), MS09-037 (KB973540_WM9) MS09-041(KB971657),MS09-042(KB960859) MS09-044(KB956744),MS09-046(KB956844) MS09-051(KB954155_WM9), MS09-051(KB975025) MS09-052(KB974112),MS09-056(KB974571)

Page 42: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 42 of 65 GE Healthcare/September 18, 2014

MS09-057(KB969059),MS09-059(KB975467) MS09-069(KB974392),MS09-071(KB974318) MS09-073(KB973904),MS10-001(KB972270) MS10-005(KB978706),MS10-007(KB975713) MS10-013(KB975560),MS10-013(KB977914) MS10-019(KB979309),MS10-026(KB977816) MS10-029(KB978338),MS10-030(KB978542) MS10-033(KB978695_WM9), MS10-033(KB979482) MS10-042(KB2229593),MS10-052(KB2115168) MS10-052(KB2115168), MS10-055(KB982665),MS10-061(KB2347290) MS10-062(KB975558_WM8), MS10-063(KB981322) MS10-065(KB2124261) MS10-074(KB2387149),MS10-076(KB982132) MS10-081(KB2296011), MS10-082(KB2378111_WM9) MS10-082(KB2378111) MS10-083(KB979687),MS10-084(KB2360937) MS10-096(KB2423089),MS10-097(KB2443105) MS10-099(KB2440591),MS11-002(KB2419632) MS11-006(KB2483185),MS11-011(KB2393802) MS11-013(KB2478971),MS11-014(KB2478960) MS11-015(KB2479943),MS11-017(KB2481109) MS11-020(KB2508429),MS11-024(KB2506212) MS11-030(KB2509553), MS11-031(KB2510531-IE8) MS11-032(KB2507618),MS11-033(KB2485663) MS11-037(KB2544893-v2), MS11-038(KB2476490) MS11-042(KB2535512),MS11-043(KB2536276-v2) MS11-052(KB2544521-IE8), MS11-056(KB2507938) MS11-062(KB2566454),MS11-071(KB2570947) MS11-075(KB2564958),MS11-080(KB2592799) MS11-092(KB2619339),MS11-093(KB2624667) MS11-097(KB2620712),MS11-100(KB2656358)MS12-001(KB2644615),MS12-002(KB2603381) MS12-003(KB2646524),MS12-004(KB2598479) MS12-004(KB2631813),MS12-005(KB2584146) MS12-006(KB2585542),MS12-009(KB2645640(KB2653956) MS12-024(KB2653956) MS12-034(KB2659262),MS12-034(KB2676562) MS12-036(KB2685939) ),MS12-043(KB2719985) MS12-045(KB2698365),MS12-048(KB2691442) MS12-049(KB2655992), MS12-053(KB2723135-v2) MS12-054(KB2705219-v2), MS12-054(KB2712808) MS12-055(KB2731847-v2), MS12-063(KB2744842-IE8) MS12-068(KB2724197),MS12-072(KB2727528) MS12-081(KB2758857 )MS13-

Page 43: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 43 of 65 GE Healthcare/September 18, 2014

004(KB2742604Q147222, Q954430,Q973688,KB936929, KB2661254-v2, KB2736233,KB2749655 KB2756822,KB951978, KB952287,KB968389KB2345886, KB2467659, KB2618444-IE8, KB2748349

Centricity Cardiology DMS Client

(v. 4.2.x)

Windows 7

SP3 –

IE 9.0

MS11-013 (KB2425227), MS11-015 (KB2479943) MS11-019 (KB2511455), MS11-024 (KB2491683) MS11-024 (KB2506212), MS11-030 (KB2509553) MS11-031 (KB2510531), MS11-032 (KB2507618) MS11-037 (KB2544893), MS11-043 (KB2536276) MS11-046 (KB2503665), MS11-048 (KB2536275) MS11-053 (KB2532531), MS11-059 (KB2560656) MS11-063 (KB2567680), MS11-071 (KB2570947) MS11-075 (KB2564958), MS11-076 (KB2579686) MS11-085 (KB2620704), MS11-090 (KB2618451) MS11-092 (KB2619339), MS11-097 (KB2620712) MS11-098 (KB2633171), MS11-100 (KB2656356) MS12-001 (KB2644615), MS12-004 (KB2631813) MS12-005 (KB2584146), MS12-006 (KB2585542) MS12-013 (KB2654428), MS12-020 (KB2621440) MS12-020 (KB2667402), MS12-024 (KB2653956) MS12-025 (KB2656373), MS12-032 (KB2688338) MS12-033 (KB2690533), MS12-034 (KB2656411) MS12-034 (KB2658846), MS12-034 (KB2659262) MS12-034 (KB2660649), MS12-034 (KB2676562) MS12-035 (KB2604115), MS12-036 (KB2685939) MS12-038 (KB2686831), MS12-043 (KB2719985) MS12-045 (KB2698365), MS12-048 (KB2691442) MS12-049 (KB2655992), MS12-054 (KB2705219) MS12-054 (KB2712808), MS12-055 (KB2731847) MS12-063 (KB2744842), MS12-068 (KB2724197) MS12-069 (KB2743555), 982861 KB2484033, KB2488113, KB2492386, KB2502285 KB2505438, KB2506928, KB2511250, KB2515325 KB2522422, KB2529073, KB2533552, KB2534111 KB2541014, KB2545698, KB2547666, KB2552343 KB2563227, KB2633952, KB2640148, KB2647753 KB2660075, KB2661254, KB2677070, KB2679255 KB2699779, KB2709630, KB2718704, KB2719857 KB2729094, KB2731771, KB2732059, KB2732487 KB2732500, KB2735855, KB2736233, KB2739159 KB2741355, KB2749655, KB2756822, KB971033 KB976902, KB982018

Definition

Centricity Cardiology INW Server A powerful server responsible to manage communication

Page 44: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 44 of 65 GE Healthcare/September 18, 2014

between critical cath and EP Lab acute care recording

devices. It also functions as a centralized storage server for

the clinical waveforms.

Mac-Lab, CardioLab, SpecialsLab and

ComboLab

Hemodynamic and Electrophysiology Recording Systems and

Workstations

Centricity Cardiology DMS Client Networked workstation in which the Centricity Cardiology

DMS client application is loaded and executed.

Centricity Cardiology DMS Server Networked architecture includes a Windows based Server

that contains database, routing, external interfaces, web and

other central functions.

Current Vulnerability A critical Microsoft Operating System flaw revealed by

Microsoft that exists on the product. The flaw has a

corrective patch distributed by Microsoft that Engineering is

in the process of validating.

Validated Security Patches A critical Microsoft security patch that Engineering has

validated on the product. The security patch can be installed

following the provided directions.

Page 45: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 45 of 65 GE Healthcare/September 18, 2014

Anti-Virus Installation for Mac-Lab\CardioLab\INW Server

Anti-virus software supports facilities in complying with privacy regulations, such as HIPAA.

Anti-Virus Requirements

WARNING:

ANTI-VIRUS SOFTWARE INSTALLATION

The System is delivered without anti-virus protection. It is recommended to have validated anti-

virus software installed on the system before connecting to any network. Lack of validated virus protection could lead to system instability or failure.

Note the following requirements:

Anti-virus software is not provided with the Mac-Lab/CardioLab system and is the customer’s

responsibility to acquire, install, and maintain.

The customer is responsible for updating anti-virus definition files.

If a virus is found contact the facility System Administrator and GE Technical Support.

Install only the anti-virus software packages listed in the listed in the Validated Anti-Virus Software

section.

Log in as an Administrator or member of that group to perform the activities in this document.

Use a language version of the validated anti-virus software that matches the operating system

language if possible. If there is no validated anti-virus software that matches the operating system

language, install the English version of the anti-virus software.

Page 46: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 46 of 65 GE Healthcare/September 18, 2014

Validated Anti-Virus Software

WARNING:

SYSTEM INSTABILITY

Do not install or use unvalidated anti-virus software (including unvalidated versions). Doing so

may result in system instability or failure. Use only validated anti-virus software in the appropriate language version.

NOTE:

If the language specific anti-virus software is not available, install the English version of anti-virus software.

The Mac-Lab/CardioLab version 6.9.6 systems have been validated to run with the software listed in the following table.

Supported Anti-Virus Software Supported Languages Supported Anti-Virus

Software Version

McAfee VirusScan Enterprise English 8.8 Patch 3

McAfee ePolicy Orchestrator (with McAfee VirusScan

Enterprise 8.8 Patch 3)

English v5.0

Symantec EndPoint Protection English 12.1.2

Trend Micro OfficeScan Client/Server Edition English 10.6 SP2

NOTE: Previously supported CA Total Defense Anti-Virus is no longer a commercially available product.

User Account Control

User Account Control is a Windows feature that prevents unauthorized changes to a computer. During certain procedures in this manual, a User Account Control message is displayed.

When this message is displayed as a result of following the procedures in this manual, elevate with the same administrator or member of that group account that you have logged in as.

Customer-Provided Server Configuration

The anti-virus management console is required to be installed on the Customer-Provided Server.

The communication between Customer-Provided Server and Mac-Lab/CardioLab devices can be accomplished in different ways including:

1. Adding to INW domain.

2. Adding to Member Server domain.

3. Cross domain authentication.

Page 47: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 47 of 65 GE Healthcare/September 18, 2014

NOTE: The customer-provided server should have two network ports. One network port to connect to the

Centricity Cardiology INW network and the second network port to connect to the hospital network.

Anti-Virus Installation Instructions

Click the anti-virus software you want to install:

Symantec EndPoint Protection McAfee VirusScan Enterprise McAfee ePolicy Orchestrator Trend Micro OfficeScan Client/Server Edition

Anti-Virus Software Common Installation Procedures

Use the procedures in this section when they are referenced in the anti-virus software installation instructions.

Disable Loopback Connection

On an Acquisition system connected to the Mac-Lab/CardioLab environment, disable the Loopback Connection to

discover all client systems with the same subnet mask on the domain.

1. Log on as Administrator or a member of that group.

2. Right-click Network on the desktop and select Properties.

3. Click Change adapter settings.

4. Right-click Loopback Connection and select Disable.

5. Restart the Acquisition system.

NOTE: Disabling the Loopback connection on the Acquisition system is required to discover all client systems with same subnet mask on the domain.

Enable Loopback Connection

On an Acquisition systems connected to the Mac-Lab/CardioLab environment, enable the Loopback Connection

using the steps below.

1. Log on as Administrator or member of that group.

2. Right-click Network on the desktop and select Properties.

3. Click Change adapter settings.

4. Right-click Loopback Connection and select Enable.

5. Restart the Acquisition system.

Configure Computer Browser Service Before Anti-Virus Installation

Check the Computer Browser service setting on networked Acquisition and Review systems to make sure it is

configured correctly.

1. Click Start > Control Panel > Network and Sharing Center.

2. Click Change advanced sharing settings.

Page 48: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 48 of 65 GE Healthcare/September 18, 2014

3. Expand Home or Work.

4. Click Turn on file and printer sharing.

5. Click Save changes.

6. Click Start > Run.

7. Type services.msc and press Enter.

8. Double-click the Computer Browser service.

9. Change the Startup type to Automatic.

10. Click Start.

11. Click OK.

12. Close the Services window.

Configure Computer Browser Service After Anti-Virus Installation

Check the Computer Browser service setting on networked Acquisition and Review systems to make sure it is

configured correctly.

1. Click Start > Run.

2. Type services.msc and press Enter.

3. Double-click the Computer Browser service.

4. Change the Startup type to Manual.

5. Click OK.

6. Close the Services window.

Page 49: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 49 of 65 GE Healthcare/September 18, 2014

Symantec EndPoint Protection

Installation Overview

Install Symantec EndPoint Protection in a networked Mac-Lab/CardioLab environment only. In a networked

environment, the Symantec EndPoint Protection must be installed on the customer-provided server and then

deployed to the Centricity Cardiology INW server and Acquisition/Review workstation as clients. Use the following instructions to install and configure Symantec EndPoint Protection for English.

Virus updates are the responsibility of the facility. Update the definitions regularly to ensure that the latest virus

protection is on the system.

Pre-Installation Guidelines

1. On the customer-provided server, make sure Symantec EndPoint Protection Manager is installed before continuing with these steps.

2. On the customer-provided server, open inbound port 8014 and name it IN_8014_Symantec and allow

inbound connections for domain, public, and private.

3. Log on as Administrator or a member of that group on all client systems (Acquisition, Review, and INW Server) to install the anti-virus software.

4. Disable the Loopback Connection. Refer to Disable Loopback Connection on page 47 for more information.

5. Configure the Computer Browser service. Refer to Configure Computer Browser Service Before Anti-Virus Installation on page 47 for more information.

Symantec EndPoint Protection Deployment Steps (Preferred Push Installation Method)

1. Click Start > All Programs > Symantec EndPoint Protection Manager > Symantec Endpoint Protection Manager.

2. Enter the appropriate user name and password to log in to Symantec Endpoint Protection Manager. (Click Yes if a security prompt displays.)

3. Check Do not show this Welcome Page again and click Close to close the welcome screen.

4. Click Home in the Symantec Endpoint Protection Manger window.

5. Select Install protection client to computers from the Common Tasks drop-down list in the top-right of the Home window.

6. Select New Package Deployment and click Next.

7. Keep the default settings and click Next.

8. Select Remote push and click Next. Wait for the Computer selection screen to appear.

9. Expand <Domain> (example: INW). Systems connected to the domain are displayed in the Computer

selection window.

NOTE: If all systems are not being recognized, click Search Network and click Find Computers. Use the search by IP address detection method to identify the client systems (Acquisition, Review, and INW Server).

10. Select all Mac-Lab/CardioLab client machines connected to the domain and click >>. The Login Credentials screen appears.

11. Enter the appropriate user name, password and domain name and click OK.

12. Make sure all selected machines appear under Install Protection Client and click Next.

Page 50: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 50 of 65 GE Healthcare/September 18, 2014

13. Click Send and wait until the Symantec anti-virus software is deployed on all client systems (Acquisition, Review, and INW Server). When finished, the Deployment Summary screen appears.

14. Click Next and then click Finish to complete the Client Deployment Wizard.

15. Restart all the client machines (Acquisition, Review, and INW Server). Login with Administrator or as a member of that group on all client machines after the restart.

Symantec EndPoint Protection Server Console Configurations 1. Select Start > All Programs > Symantec EndPoint Protection Manager > Symantec EndPoint Protection

Manager. The Symantec EndPoint Protection Manager log on window opens.

2. Enter the appropriate Symantec Endpoint Protection Manager Console password and click Log On.

3. Select the Policies tab and click Virus and Spyware Protection under Policies. The Virus and Spyware Protection Policies window opens.

4. Click Add a Virus and Spyware Protection policy under Tasks. The Virus and Spyware Protection window

opens.

5. Under Windows Settings > Scheduled Scans, click Administrator-Defined Scans.

6. Select Daily Scheduled Scan and click Edit. The Edit Scheduled Scan window opens.

7. Change scan name and description to Weekly Scheduled Scan and Weekly Scan at 00:00 respectively.

8. Select Scan type as Full Scan.

9. Select the Schedule tab.

10. Under Scanning Schedule, select Weekly and change the time to 00:00.

11. Under Scan Duration uncheck Randomize scan start time within this period (recommended in VMs) and select Scan until finished (recommended to optimize scan performance).

12. Under Missed scheduled Scans uncheck Retry the scan within.

13. Select the Notifications tab.

14. Uncheck Display a notification message on the infected computer and click OK.

15. Select the Advanced tab in the Administrator-Defined Scans window.

16. Under Scheduled Scans uncheck Delay scheduled scans when running on batteries, Allow user-defined

scheduled scans to run when scan author is not logged on and Display Notification about detections when the user logs on.

17. Under Startup and Triggered Scans uncheck Run an Active Scan when new definitions arrive.

18. Under Windows Settings > Protection Technology, click Auto-Protect.

19. Select the Scan Details tab and select and lock Enable Auto-Protect.

20. Select the Notifications tab and uncheck and lock Display a notification message on the infected computer and Display the Auto-Protect results dialog on the infected Computer.

21. Select the Advanced tab and under Auto-Protect Reloading and Enablement, uncheck and lock the When Auto-Protect is disabled, Enable after: option.

22. Under Additional Options click File Cache. The File Cache window opens.

23. Uncheck Rescan cache when new definitions load and click OK.

Page 51: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 51 of 65 GE Healthcare/September 18, 2014

24. Under Windows Settings > Protection Technology, click Download Protection.

25. Select the Notifications tab and uncheck and lock Display a notification message on the infected computer.

26. Under Windows Settings > Email Scans, click Internet Email Auto-Protect.

27. Select the Notifications tab and uncheck and lock Display a notification message on the infected computer, Display a progress indicator when email is being sent, and Display a notification area icon.

28. Under Windows Settings > Email Scans, click Microsoft Outlook Auto-Protect.

29. Select the Notifications tab and uncheck and lock Display a notification message on the infected computer.

30. Under Windows Settings > Email Scans, click Lotus Notes Auto-Protect.

31. Select the Notifications tab and uncheck and lock Display a notification message on infected computer.

32. Under Windows Settings > Advanced Options, click Quarantine.

33. Under When New Virus Definitions Arrive, select Do nothing.

34. Under Windows Settings > Advanced Options, click Miscellaneous.

35. Select the Notifications tab and uncheck Display a notification message on the client computer when

definitions are outdated, Display a notification message on the client computer when Symantec

Endpoint Protection is running without virus definitions and Display error messages with a URL to a solution.

36. Click OK to close Virus and Spyware Protection policy.

37. Click Yes at the Assign Policies message box.

38. Select My Company and click Assign.

39. Click Yes at the message box.

40. Under Policies click LiveUpdate.

41. Select LiveUpdate Settings policy and under Tasks, click Edit the policy.

42. Under Overview > Windows Settings, click Server Settings.

43. Under Internal or External LiveUpdate Server, ensure Use the default management server is selected and uncheck Use a LiveUpdate server.

44. Click OK.

45. Click Clients from left pane and select the Policies tab.

46. Uncheck Inherit policies and settings from parent group “My Company” and click Communications Settings under Location-Independent Policies and Settings.

47. Under Download, make sure Download policies and content from the management server is checked and Push mode is selected.

48. Click OK.

49. Click General Settings under Location-independent Policies and Settings.

50. Select the Tamper Protection tab and uncheck and lock Protect Symantec security software from being tampered with or shut down.

Page 52: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 52 of 65 GE Healthcare/September 18, 2014

51. Click OK.

52. Click Admin and select Servers.

53. Under Servers, select Local Site (My Site).

54. Under Tasks, select Edit Site Properties. The Site Properties for Locate Site (My Site) window opens.

55. Select LiveUpdate tab and under Download Schedule ensure the schedule is set to Every 4 hour(s).

56. Click OK.

57. Click Policies and select Firewall.

58. Select Firewall policy and under Tasks click Edit the policy. The Firewall policy window opens.

59. Click Protection and Stealth and under Protection Settings uncheck Automatically block an attacker’s IP address.

60. Click OK.

61. Click Log Off and close the Symantec EndPoint Protection Manager Console. Make sure Symantec Endpoint

Protection Policies are pushed in client systems.

Symantec EndPoint Protection Post Installation Guidelines

1. Enable the Loopback Connection. Refer to Enable Loopback Connection on page 47 for more information.

2. Configure the Computer Browser service. Refer to Configure Computer Browser Service After Anti-Virus Installation on page 48 for more information.

Page 53: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 53 of 65 GE Healthcare/September 18, 2014

McAfee VirusScan Enterprise

Installation Overview

McAfee VirusScan Enterprise should be installed on an individual Mac-Lab/CardioLab system and it should be managed individually. Use the following instructions to install and configure McAfee VirusScan Enterprise for

English.

Virus updates are the responsibility of the facility. Update the definitions regularly to ensure that the latest virus

protection is on the system.

McAfee VirusScan Enterprise Installation Procedure

1. Log on as Administrator or as a member of that group.

2. Insert the McAfee VirusScan Enterprise 8.8 Patch 3 CD into the CD drive.

3. Double-click SetupVSE.Exe. The Windows Defender dialog appears.

4. Click Yes. The McAfee VirusScan Enterprise Setup screen appears.

5. Click Next. The McAfee End User License Agreement screen appears.

6. Read the license agreement and complete any necessary fields, click OK when finished.

7. Select Typical and click Next.

8. Select Standard Protection and click Next.

9. Click Install and wait for the installation to complete. After successful installation of McAfee VirusScan Enterprise, the McAfee Virus Scan Enterprise Setup has completed successfully screen appears.

10. Uncheck the Run On-Demand Scan checkbox and click Finish.

11. If the Update in Progress window appears, click Cancel.

12. If a message box to restart the system appears, click OK.

13. Restart the system.

14. Log on as Administrator or as a member of that group.

McAfee VirusScan Enterprise Configuration

1. Right-click McAfee in the system tray and select On-Access Scan Properties.

2. Select the ScriptScan tab. The ScriptScan window opens.

3. Clear the Enable scanning of scripts check box.

4. Select the Messages tab. The Messages window opens.

5. Uncheck the Show the messages dialog when a threat is detected and display the specified text in the message check box.

6. Click Apply.

7. Click OK to close the On-Access Scan Properties window.

8. Select Start > All Programs > McAfee > VirusScan Console. The VirusScan Console window opens.

9. Select Tools > Alerts. The Alert Properties window opens.

Page 54: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 54 of 65 GE Healthcare/September 18, 2014

10. Uncheck the On-Access Scan, On-Demand Scan and scheduled scans, Email Scan and AutoUpdate check

boxes.

11. Click Destination. The Alert Manager Client Configuration window opens.

12. Select the Disable alerting check box.

13. Click OK. The Alert Properties window opens.

14. Select the Additional Alerting Options tab.

15. Select the Suppress all alerts (severities 0 to 4) option from the Severity Filter drop-down list.

16. Select the Alert Manager Alerts tab.

17. Clear the Access Protection check box.

18. Click Apply.

19. Click OK to close the Alert Properties window.

20. Right-click AutoUpdate on the VirusScan Console.

21. Click Properties. The McAfee AutoUpdate Properties – AutoUpdate window opens.

22. Click Schedule. The Schedule Settings window opens.

23. Clear the Enable (scheduled task runs at specified time) check box.

24. Click Apply.

25. Click OK to close the Schedule Settings window.

26. Click OK to close the McAfee AutoUpdate Properties – AutoUpdate window.

27. Right-click Full Scan on the VirusScan Console.

28. Click Properties. The On Demand Scan Properties window opens.

29. Click Schedule. The Schedule Settings window opens.

30. Check the Enable (scheduled task runs at specified time) check box.

31. Select the Schedule tab.

32. Select Weekly from Run Task, 12:00 AM from Start Time. check Sunday from Schedule Task Weekly.

33. Click OK. The On Demand Scan Properties - Full Scan window opens.

34. Select the Exclusions tab.

35. Click Exclusions. The Set Exclusions window opens.

36. Click Add.

37. Click Browse and navigate to C:\Program Files\GE Healthcare\MLCL and D:\GEData\Studies\ folders one at a time and select the Also exclude subfolders checkbox.

38. Click OK.

39. In the Set Exclusions window, make sure the C:\Program Files\GE Healthcare\MLCL and D:\GEData\Studies\ folders display.

40. Click OK.

Page 55: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 55 of 65 GE Healthcare/September 18, 2014

41. Click OK to close the On Demand Scan Properties – Full Scan window.

42. Close the VirusScan Console.

Page 56: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 56 of 65 GE Healthcare/September 18, 2014

McAfee ePolicy Orchestrator

Installation Overview

Install McAfee ePolicy Orchestrator on a networked Mac-Lab/CardioLab environment only. McAfee ePolicy Orchestrator must be installed on a customer-provided server and McAfee VirusScan Enterprise should be deployed to the Centricity Cardiology INW server and Acquisition/Review workstations as a client. Use the following instructions to install and configure McAfee ePolicy Orchestrator for English.

Virus updates are the responsibility of the facility. Update the definitions regularly to ensure that the latest virus

protection is on the system.

Pre-Installation Guidelines

1. Make sure McAfee ePolicy Orchestrator Console is installed on the customer provided server before continuing with these steps.

2. On the customer-provided server, open inbound port 443 and name it IN_443_McAfee and allow inbound

connections for domain, public, and private.

3. Log on as Administrator or a member of that group on all client systems (Acquisition, Review, and INW Server) to install the anti-virus software.

4. Disable the Loopback Connection. Refer to Disable Loopback Connection on page 47 for more information.

McAfee ePolicy Orchestrator Deployment Steps (Preferred Push Installation Method)

1. Select Start > All Programs > McAfee > ePolicy Orchestrator > Launch McAfee ePolicy Orchestrator 5.0.0 Console to log on to the ePolicy Orchestrator console.

NOTE: Click Continue with this website if the Security Alert message box appears.

2. Enter the appropriate username and password and click Log On.

3. Select Menu > Configuration > Server Settings > Port.

4. Record the Agent-to-server communication port number.

5. On the customer-provided server, open the Agent-to-server communication port as an inbound port and name it IN_<port number>_McAfee.

6. Select Start > All Programs > McAfee > ePolicy Orchestrator > Launch McAfee ePolicy Orchestrator 5.0.0 Console to log on to the ePolicy Orchestrator console.

NOTE: Click Continue with this website if the Security Alert message box appears.

7. Enter the appropriate username and password and click Log On.

8. Select Menu > Systems > Systems Tree. The System Tree window opens.

9. Click My Organization and with the focus on My Organization click System Tree Actions > New Systems

from the bottom left corner of the screen.

10. Select Push agents and add systems to the current group (My Organization) and click Browse.

11. Enter the domain administrator username and password and click OK.

12. Select the INW domain from the Domain drop-down list.

13. Select the client machines (Acquisition, Review, and INW Server) connected to the domain and click OK.

Page 57: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 57 of 65 GE Healthcare/September 18, 2014

14. Select Agent Version as McAfee Agent for Windows 4.8.0 (Current). Enter appropriate domain administrator username and password and click OK.

15. In client machines (Acquisition, Review, and INW Server) make sure the C:\Program Files\McAfee\Common

Framework directory is present and McAfee Agent is installed in the same directory.

NOTE: For the INW Server make sure the C:\Program Files (x86)\McAfee\Common Framework directory is present and McAfee Agent is installed in the same directory.

16. Restart the client machines (Acquisition, Review, and INW Server).

17. Click Start > All Programs > McAfee > ePolicy Orchestrator > Launch McAfee ePolicy Orchestrator 5.0.0 Console.

18. Enter the appropriate username and password and click Log On.

19. Click Menu > Systems > System Tree.

20. Click My Organization and with the focus on My Organization click the Assigned Client Tasks tab.

21. Click Actions > New Client Task Assignment button at the bottom of the screen. The Client Task Assignment Builder screen appears.

22. Select the following:

a. Product: McAfee Agent

b. Task Type: Product Deployment

c. Task name: Create New Task

23. On the Client Task Catalog: New Task- McAfee Agent: Product Deployment screen, complete the fields as

follows:

a. Task Name: Enter the appropriate task name

b. Target platforms: Windows

c. Products and components: VirusScan Enterprise

d. Options: Run at every policy enforcement (Windows only)

24. Click Save.

25. In the 1 select Task screen, select the following:

a. Product: McAfee Agent

b. Task Type: Product Deployment

c. Task Name: Newly created task name

26. Click Next. The 2 Schedule screen appears.

27. Select Run immediately from Schedule type drop-down list.

28. Click Next. The 3 Summary screen appears.

29. Click Save. The System Tree screen appears.

30. Select the Systems tab and then select all the client machines (Acquisition, Review, and INW Server) which

are connected to the domain.

Page 58: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 58 of 65 GE Healthcare/September 18, 2014

31. Click Wake up Agents at bottom of the window.

32. Keep default settings and click OK.

33. Restart all the client machines (Acquisition, Review, and INW Server) and log in with Administrator or a member of that group on all client machines.

34. Click the Log Off link to close the McAfee ePolicy Orchestrator Console.

McAfee ePolicy Orchestrator Server Console Configuration

1. Select Start > All Programs > McAfee > ePolicy Orchestrator > Launch McAfee ePolicy Orchestrator 5.0.0 Console to log on to the ePolicy Orchestrator console.

NOTE: Click Continue with this website if the Security Alert message box appears.

2. Enter the appropriate Username and Password. The ePO Summary window opens.

3. Select Menu > Systems > Systems Tree. The System Tree window opens.

4. Click My Organization.

5. Select the Assigned Policies tab. The Assigned Policies screen opens.

6. From the Product drop-down list, select VirusScan Enterprise 8.8.0. The Assigned Policies window for

VirusScan Enterprise 8.8.0 opens.

7. Click My Default for On-Access General Policies. The General window opens.

8. Select Workstation from the Settings for drop-down list. Click ScriptScan and uncheck Enable scanning of scripts.

9. Click Messages. The Messages window opens.

10. Uncheck Show the messages dialog box when a threat is detected and display the specified text in the message.

11. Select Server from the Settings for drop-down list.

12. Click ScriptScan and ensure Enable scanning of scripts is unchecked.

13. Click Messages. The Messages window opens.

14. Uncheck the Show the messages dialog box when a threat is detected and display the specified text in the message.

15. Click Save.

16. Select My Default for Buffer Overflow Protection Policies. The Buffer Overflow Protection window opens.

17. Select Workstation from the Settings for drop-down list and uncheck Show the messages dialog box when a buffer overflow is detected.

18. Select Server from the Settings for drop-down list and uncheck Show the messages dialog box when a buffer overflow is detected.

19. Click Save.

20. Click My Default for Alert Policies. The Alert Manager Alerts window opens.

21. Select Workstation from the Settings for drop-down list and uncheck On-Access Scan, On- Demand Scan and scheduled scans, Email Scan and AutoUpdate.

22. Check Disable alerting.

Page 59: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 59 of 65 GE Healthcare/September 18, 2014

23. Click Additional Alerting Options. The Additional Alerting Options window opens.

24. From the Severity Filters drop-down menu, select Suppress all alerts (severities 0 to 4).

25. Select Server from the Settings for drop-down list and select the Alert Manager Alerts tab. The Alert Manager Alerts window opens.

26. Uncheck On-Access Scan, On-Demand Scan and scheduled scans, Email Scan and AutoUpdate.

27. Check Disable alerting.

28. Click Additional Alerting Options. The Additional Alerting Options window opens.

29. From the Severity Filters drop-down menu, select Suppress all alerts (severities 0 to 4).

30. Click Save.

31. Click My Default for On-Access Default Processes Policies. The Processes window opens.

32. Select Workstation from the Settings for drop-down list and ensure Configure one scanning policy for all processes is selected.

33. Click the Exclusions tab. The Exclusions window opens.

34. Click Add and select By pattern.

35. Enter the C:\Program Files\GE Healthcare\MLCL and D:\GEData\Studies folder names and select Also exclude subfolders.

36. Click OK.

37. Select Server from Settings for drop-down list and select the Processes tab.

38. Ensure Configure one scanning policy for all processes is selected.

39. Select the Exclusions tab. The Exclusions window opens.

40. Click Add and select By pattern.

41. Enter C:\Program Files (x86)\GE Healthcare\MLCL and select Also exclude subfolders.

42. Click OK.

43. Click Save.

44. From the Product drop-down menu, select McAfee Agent. The Policies window for McAfee Agent opens.

45. Click My Default for Repository. The Repositories window opens.

NOTE: Click Close for Internet Explorer Security Message Box.

46. Click Proxy. The Proxy window opens.

47. Select Use Internet Explorer settings (For Windows)/System Preferences settings (For Mac OSX).

48. Click Save.

49. Click Systems.

50. Select all the client systems (Acquisition, Review and Centricity Cardiology INW server) into which the configured policies are to be deployed.

51. Select Wake Up Agents. The Wake Up Agent window opens.

52. Click OK.

Page 60: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 60 of 65 GE Healthcare/September 18, 2014

53. Log off ePolicy Orchestrator.

McAfee ePolicy Orchestrator Post Installation

Enable the Loopback Connection. Refer to Enable Loopback Connection on page 47 for more information.

Page 61: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 61 of 65 GE Healthcare/September 18, 2014

Trend Micro OfficeScan Client/Server Edition

Installation Overview

Install Trend Micro OfficeScan Client/Server Edition on a networked Mac-Lab/CardioLab environment only. Trend Micro OfficeScan must be installed on the customer-provided server and then deployed to Centricity Cardiology INW server and Acquisition/Review workstation as clients. Use the following instructions to install Trend Micro OfficeScan Client/Server Edition for English.

Virus updates are the responsibility of the facility. Update the definitions regularly to ensure that the latest virus

protection is on the system.

Pre-Installation Guidelines

1. On the customer-provided server, make sure Office Scan Web Console is installed before continuing with these steps.

2. On the customer-provided server, open inbound port 8080 and name it IN_8080_OSCE and allow inbound

connections for domain, public, and private.

3. Log on as Administrator or member of that group on all client systems (Acquisition, Review, and INW Server) to install the anti-virus software.

4. Disable the Loopback Connection. Refer to Disable Loopback Connection on page 47 for more information.

5. Configure the Computer Browser service. Refer to Configure Computer Browser Service Before Anti-Virus Installation on page 47 for more information.

Trend Micro OfficeScan Deployment Steps (Preferred Push Installation Method)

1. Click Start > All Programs > TrendMicro OfficeScan server - <server name> > Office Scan Web Console.

NOTE: Continue by selecting Continue to this website (not recommended). In the Security Alert window, check In the future, do not show this warning and click OK.

2. If you receive a certificate error indicating that the site is not trusted, manage your certificates to include Trend Micro OfficeScan.

3. If prompted, install the AtxEnc add-ons. The Security Warning screen will appear.

4. Click Install.

5. Enter appropriate username and password and click Log On.

6. If prompted, click Update Now to install new widgets. Wait until the new widgets are updated. The update

is completed screen will appear.

7. Click OK.

8. From the left side menu bar, click Networked Computers > Client Installation > Remote.

9. If prompted, install the AtxConsole add-ons. The Security Warning screen will appear.

10. Click Install.

11. Double-click My Company in the Remote Installation window. All domains will be listed under My Company.

12. Expand the appropriate domain (Example: INW) from the list. All systems connected to the domain appear.

Page 62: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 62 of 65 GE Healthcare/September 18, 2014

13. If domains or systems are not listed in the Domain and Computers window, do the following on each of the

client systems (Acquisition, Review, and INW Server):

a. Click Start > Run.

b. Enter \\<customer_provided_server_IP_address> and press Enter.

c. Navigate to \\<customer_provided_server_IP _address>\ofsscan and double-click AutoPcc.exe.

d. Restart the client systems when the installation is complete.

e. Log in as Administrator or a member of that group on all client machines and wait until the Trend Micro OfficeScan icon in system tray changes to blue.

f. Click the Log Off link to close the OfficeScan Web Console.

g. Skip the remaining steps in this procedure and go to the Trend Micro OfficeScan Server Console Configuration procedure.

14. Select the client machines (Acquisition, Review, and INW Server) and click Add.

15. Enter the appropriate <domain name>\username and password and click Log on.

16. Select the client machines (Acquisition, Review, and INW Server) one at a time from the Selected Computers pane and click Install.

17. Click Yes at the confirmation box.

18. Click OK at the Number of clients to which notifications were sent message box.

19. Restart all the client machines (Acquisition, Review, and INW Server) and Log in as Administrator or a

member of that group on all client machines and wait until the Trend Micro OfficeScan icon in system tray changes to blue with sin wave symbol.

20. Click the Log Off link to close the OfficeScan Web Console.

Trend Micro OfficeScan Server Console Configuration

1. Select Start > All Programs > TrendMicro Office Scan server <servername> > Office Scan Web Console. The Trend Micro OfficeScan Login window appears.

2. Enter the appropriate user name and password and click Login. The Summary window opens.

3. From the left side pane, select the Networked Computers > Client Management link.

4. On the right side, select OfficeScan Server.

5. From the Settings options, select Privileges and Other Settings.

6. Select only the following options in the Privileges tab and clear the remaining options:

o Scan Privileges > Configure Manual Scan Settings.

o Scan Privileges > Configure Real-time Scan Settings.

o Scan Privileges > Configure Scheduled Scan Settings.

o Proxy Setting Privileges > Allow the client user to configure proxy settings.

o Uninstallation > Require a password for the user to uninstall the OfficeScan Client. Enter a

suitable password. o Unloading > Require a password for the user to unload the OfficeScan client. Enter a suitable

password.

7. Select the Other Settings tab.

8. Select Client Security Settings > Normal and clear the remaining options.

Page 63: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 63 of 65 GE Healthcare/September 18, 2014

9. Click Apply to All Clients.

10. Click Close to close the Privileges and Other Settings window.

11. From the left side pane, select the Client Management link.

12. On the right side, select OfficeScan Server.

13. From the Settings options, select Scan Settings > Scan Now Settings.

14. Select only the following options in the Target tab and clear the remaining options:

o Files to Scan > File types scanned by IntelliScan.

o Scan Settings > Scan Compressed files.

o Scan Settings > Scan OLE objects.

o Virus/Malware Scan Settings only > Scan boot area.

o CPU Usage > Low.

o Scan Exclusion > Enable scan exclusion.

o Scan Exclusion > Apply scan exclusion settings to all scan types.

o Scan Exclusion List (Directories) > Exclude directories where Trend Micro products are installed

and select “Add path to client Computers Exclusion list”. o Enter the C:\Program Files (x86)\GE Healthcare\MLCL, C:\Program Files\GE Healthcare\MLCL

and D:\GEData\Studies folders one at a time in the directory path for Exclusion List and click Add.

15. Click Apply to All Clients.

16. The exclusion list on this screen will replace the exclusion list on the clients or domains you selected in the client tree earlier. Do you want to proceed? Message will appear. Click OK.

17. Click Close to close the Scan Now Settings page.

18. From the left side pane, select the Client Management link.

19. On the right side, select OfficeScan Server.

20. From the Settings options, select Settings->Scan Settings->Real-time Scan Settings.

21. Select the Target tab. Select only the following options and clear the remaining options:

o Enable Virus/Malware scan.

o User Activity on Files > created/modified and retrieved.

o Files to Scan > File types scanned by IntelliScan.

o Virus/Malware Scan Settings Only > Enable IntelliTrap.

o Scan Exclusion > Enable scan exclusion.

o Scan Exclusion > Apply scan exclusion settings to all scan types.

o Scan Exclusion List (Directories) > Exclude directories where Trend Micro products are installed.

o Make sure the C:\Program Files (x86)\GE Healthcare\MLCL, C:\Program Files \GE Healthcare\MLCL and D:\GEData\Studies paths are present in the Exclusion List.

22. Click the Action tab.

23. Keep the default settings and clear Virus/Malware > Display a notification message on the client

computer when Virus/Malware is detected option and Spyware/Grayware->Display a notification message on the client computer when spyware/Grayware is detected.

24. Click Apply to All Clients.

25. Click Close to close the Real-time Scan Settings page.

26. From the left side pane, select the Client Management link.

27. On the right side, select OfficeScan Server.

Page 64: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 64 of 65 GE Healthcare/September 18, 2014

28. From the Settings options, select Scan settings-> Scheduled Scan Settings.

29. Select the Target tab. Select only the following options and clear the remaining options:

o Enable Virus/Malware scan.

o Schedule > Weekly, every (Sunday).

o Files to Scan > File types scanned by IntelliScan.

o Virus/Malware Scan settings only > Scan boot area.

o CPU Usage > Low.

o Scan Exclusion > Enable scan exclusion.

o Scan Exclusion > Apply scan exclusion settings to all scan types.

o Scan Exclusion List (Directories) > Exclude directories where Trend Micro products are installed.

o Make sure the C:\Program Files (x86)\GE Healthcare\MLCL, C:\Program Files \GE Healthcare\MLCL and D:\GEData\Studies paths are present in the Exclusion List.

30. Click the Action tab.

31. Keep the default settings and uncheck the Virus/Malware > Display a notification message on the client

computer when Virus/Malware is detected and Spyware/Grayware-> Display a notification message on the client computer when spyware/Grayware is detected options.

32. Click Apply to All Clients.

33. Click Close to close the Scheduled Scan Settings page.

34. From the left side pane, select the Networked Computers > Global Client Settings link.

35. Select only the following options and clear the remaining options:

o Scan Settings > Configure Scan settings for large compressed files.

o Scan Settings > Do not scan files in the compressed file if the size exceeds 2 MB.

o Scan Settings > In a compressed file scan only the first 100 files.

o Scan Settings > Exclude the OfficeScan server database folder from Real-time Scan.

o Scan Settings > Exclude Microsoft Exchange server folders and files from scans.

o Reserved Disk Space > Reserve 60 MB of disk space for updates. o Proxy Configuration > Automatically detect settings.

NOTE: It is important to clear the Alert Settings > Display a notification message if the client computer

needs to restart to load a kernel driver.

36. Click Save.

37. Click Log off and close the OfficeScan Web Console.

Trend Micro OfficeScan Post Installation Guidelines

1. Enable the Loopback Connection. Refer to Enable Loopback Connection on page 47 for more information.

2. Configure the Computer Browser service. Refer to Configure Computer Browser Service After Anti-Virus Installation on page 48 for more information.

Page 65: Invasive Cardiology Security Website › ~ › media › downloads › us › support... · The Mac-Lab IT/XT/XTi and CardioLab IT/XT/XTi vulnerability validation criteria are as

GE Healthcare

Page 65 of 65 GE Healthcare/September 18, 2014

Contact Information

If you have any additional questions, please contact our Technical Support Department.

Notes:

Support for version 6.5.6/6.8/6.8.1

As of June 2014, all Mac-Lab/CardioLab/ComboLab/INW Server systems at version 6.5.6/6.8/6.8.1 will no longer

have new security patches qualified.

Support for Windows Server 2008 R2

As of April 2013, Microsoft no longer provides security patches for Windows Server 2008 R2. Therefore, MLCL v6.9

Server systems will no longer have new security patches qualified.

Microsoft Office Security Patch Support

Currently qualified Microsoft Office 2007 SP2 security patches are eligible for MLCL 6.5.6/6.8/6.8.1 Software Only

Systems. Office Language Pack 2007 SP3 (http://support.microsoft.com/kb/2526086) is a pre-requisite for the

installation of Microsoft Office 2007 SP3 security patches on MLCL v6.5.6/6.8/6.8.1 Software Only Systems.

Support for version 6.5.3/6.5.4

As of October 2010, all Mac-Lab/CardioLab/ComboLab/INW Server systems at version 6.5.3/6.5.4 will no longer

have new security patches qualified.

Support for Windows NT

Microsoft no longer provides security patches or support for the Windows NT Operating System. There will be no

new security patches for the Mac-Lab/CardioLab 7000/4000/2000 5.x systems.