CVE-2024-55957
HIGHThermo Fisher Scientific Xcalibur <4.7 SP1 & Thermo Foundation ICSW...
Title source: llmDescription
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems.
References (2)
Core 2
Core References
Various Sources
https://assets.thermofisher.com/TFS-Assets/CORP/Product-Guides/Thermo_Scientific_Xcalibur_and_Foundation.pdf
Various Sources
https://thermofisher.com
Scores
CVSS v3
7.8
EPSS
0.0016
EPSS Percentile
5.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Published
Jan 22, 2025
Tracked Since
Feb 18, 2026