---
cve: "CVE-2024-50590"
severity: "HIGH"
cvss: 7.8
epss: "19%"
vendor: "HASOMED"
kev: false
exploited: false
published: "2024-11-08 12:15:14"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T10:27:22+02:00"
---

# CVE-2024-50590

> 7.8 HIGH

## Beschreibung

Attackers with local access to the medical office computer can 
escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by 
overwriting one of two Elefant service binaries with weak permissions. The default installation directory of Elefant is "C:\Elefant1" which is 
writable for all users. In addition, the Elefant installer registers two
 Firebird database services which are running as “NT AUTHORITY\SYSTEM”. 

Path: C:\Elefant1\Firebird_2\bin\fbserver.exe

Path: C:\Elefant1\Firebird_2\bin\fbguard.exe


Both service binaries are user writable. This means that a local 
attacker can rename one of the service binaries, replace the service 
executable with a new executable, and then restart the system. Once the 
system has rebooted, the new service binary is executed as "NT 
AUTHORITY\SYSTEM".

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://r.sec-consult.com/hasomed>
- <https://hasomed.de/produkte/elefant/>
- <http://seclists.org/fulldisclosure/2024/Nov/3>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-50590) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
