First published: Mon Jun 19 2023(Updated: )
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may be executed with the administrative privilege.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ricoh Printer Driver Packager Nx | >=1.0.02<1.1.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30759 is a vulnerability in the Printer Driver Packager NX software, version 1.0.02 to 1.1.25, where the driver installation package fails to detect its modification and may spawn an unexpected process with administrative privilege.
If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary process can be executed with administrative privilege.
CVE-2023-30759 has a severity rating of 7.8 (High).
To fix CVE-2023-30759, users should update the Printer Driver Packager NX software to version 1.1.26 or later.
You can find more information about CVE-2023-30759 at the following references: [link1](https://jvn.jp/en/vu/JVNVU92207133/), [link2](https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000048-2023-000001), [link3](https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2023-000001)