Unquoted Service Path Lücke in Mediconta von Infonet Software - CVE-2023-54336
⚠️ CVE-Referenzen:
CVE-2023-54336
Zusammenfassung
In der Version 3.7.27 des Mediconta-Produkts von Infonet Software wurde eine Schwachstelle aufgrund eines unquoted Service Paths entdeckt (CVE-2023-54336). Lokale Nutzer können diese Lücke ausnutzen, um bösartigen Code mit LocalSystem-Rechten auszuführen. Anwender sollten dringend Updates installieren, um das Risiko einer Kompromittierung zu mindern.
Infonetsoftware - Mediconta - HIGH - CVE-2023-54336.
Mediconta version 3.7.27 contains a vulnerability in the 'servermedicontservice' component due to an unquoted service path. This flaw allows local users to exploit the unquoted path located in 'C:\Program Files (x86)\medicont3\' to inject malicious code. If successfully exploited, the injected code can run with LocalSystem permissions during the service startup, potentially leading to unauthorized system control and privilege escalation. It is crucial for users of Mediconta to apply updates and follow security best practices to mitigate this risk.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io