Thermo Scientific Xcalibur and Foundation software for Windows were found to contain a local privilege escalation flaw tracked as CVE-2024-55957, caused by improper access controls that let low-privileged users overwrite executables and DLLs in the Thermo Foundation installation directory. Because one or more associated services run as NT AUTHORITY\SYSTEM, an attacker could replace service binaries or libraries and gain elevated privileges after a service restart or reboot. Tier Zero Security said it discovered the issue during an October 2024 engagement, and Thermo Fisher issued a security bulletin and patch on January 22, 2025.
A later review found the fix was incomplete: in a new installation path, Authenticated Users still had full write permissions on service executables and DLLs, leaving the underlying escalation path in place. Tier Zero Security reported the residual issue to Thermo Fisher on February 8, 2025, and Thermo Fisher later updated its bulletin to instruct customers to contact technical support for a script to correct file permissions. At the time of the follow-up disclosure, no fully patched software release had been made publicly available, leaving affected organizations dependent on vendor guidance and manual remediation.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Thermo Fisher updated its original security bulletin to instruct customers to contact technical support for a script to correct the affected file permissions. The update indicated a workaround-style remediation rather than a fully patched software release.
Tier Zero Security reported to Thermo Fisher that the January remediation was incomplete. The report stated that insecure file permissions still allowed the local privilege escalation condition to remain.
Thermo Fisher released a security bulletin and patch for CVE-2024-55957. The issue affected Thermo Scientific Xcalibur and Foundation software on Windows.
Tier Zero Security discovered a local privilege escalation vulnerability affecting Thermo Scientific Xcalibur and Foundation software during an engagement. The flaw involved improper access controls that let low-privileged users overwrite executables and DLLs, including service binaries running as SYSTEM.
After reviewing the newly patched version, Tier Zero Security found the software had moved to a new installation path but Authenticated Users still had full write permissions on affected executables and DLLs. This showed the underlying privilege escalation issue persisted despite the patch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
tierzerosecurity.co.nz
Open sourcetierzerosecurity.co.nz
Open sourceassets.thermofisher.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.