CVE-2023-54336

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Mediconta 3.7.27 contiene una vulnerabilidad de ruta de servicio sin comillas en el servicio servermedicontservice que permite a usuarios locales ejecutar código potencialmente con privilegios elevados. Los atacantes pueden explotar la ruta sin comillas en C:\Program Files (x86)\medicont3\ para inyectar código malicioso que se ejecutaría con permisos de LocalSystem durante el inicio del servicio.

13 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:16

Updated : 2026-04-15 00:35


NVD link : CVE-2023-54336

Mitre link : CVE-2023-54336

CVE.ORG link : CVE-2023-54336


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element