PT-2024-34346 · Microsoft+1 · Windows+1

Daniel Hirschberger

+2

·

Published

2024-11-08

·

Updated

2024-11-08

·

CVE-2024-50591

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Elefant Software Updater (ESU) (affected versions not specified)
Description: An attacker with local access to a medical office computer can escalate their Windows user privileges to "NT AUTHORITYSYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The vulnerability can be exploited by communicating with the Elefant Update Service, which is running as "SYSTEM" via Windows Named Pipes. The Elefant Software Updater (ESU) consists of two components: an ESU service that runs as "NT AUTHORITYSYSTEM" and an ESU tray client that communicates with the service to update or repair the installation and is running with user permissions. The communication is implemented using named pipes. A crafted message of type MessageType.SupportServiceInfos can be sent to the local ESU service to inject commands, which are then executed as "NT AUTHORITYSYSTEM".
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-50591

Affected Products

Elefant Software Updater
Windows