Hacking these medical pumps is as easy as copying a booby-trapped file over the network


Copying a cab over smb is one thing...

... and once copied, it should sit there, like any other file copied to a remote system's windows share - but that does not mean that the software should actually randomly execute it - unless the app came with some sort of update routine that did no checking on the validity of the file that it received. Blindly trusting user inputs is always a bad thing...

