CVE-2023-30759: CSRF
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may be executed with the administrative privilege.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30759?
CVE-2023-30759 is a vulnerability in the Printer Driver Packager NX software, version 1.0.02 to 1.1.25, where the driver installation package fails to detect its modification and may spawn an unexpected process with administrative privilege.
How does CVE-2023-30759 impact the target PC?
If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary process can be executed with administrative privilege.
What is the severity of CVE-2023-30759?
CVE-2023-30759 has a severity rating of 7.8 (High).
How can I fix CVE-2023-30759?
To fix CVE-2023-30759, users should update the Printer Driver Packager NX software to version 1.1.26 or later.
Where can I find more information about CVE-2023-30759?
You can find more information about CVE-2023-30759 at the following references: [link1](https://jvn.jp/en/vu/JVNVU92207133/), [link2](https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000048-2023-000001), [link3](https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2023-000001)