PT-2024-34346 · Microsoft+1 · Windows+1
Daniel Hirschberger
+2
·
Published
2024-11-08
·
Updated
2024-11-08
·
CVE-2024-50591
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Elefant Software Updater (ESU) (affected versions not specified)
Description:
An attacker with local access to a medical office computer can escalate their Windows user privileges to "NT AUTHORITYSYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The vulnerability can be exploited by communicating with the Elefant Update Service, which is running as "SYSTEM" via Windows Named Pipes. The Elefant Software Updater (ESU) consists of two components: an ESU service that runs as "NT AUTHORITYSYSTEM" and an ESU tray client that communicates with the service to update or repair the installation and is running with user permissions. The communication is implemented using named pipes. A crafted message of type
MessageType.SupportServiceInfos can be sent to the local ESU service to inject commands, which are then executed as "NT AUTHORITYSYSTEM".Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elefant Software Updater
Windows