CVE-2023-32232: Critical severity vasion printerlogic client vulnerability
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repair, a PrinterLogic binary is called by the installer to configure the device. This window is not hidden, and is running with elevated privileges. A standard user can break out of this window, obtaining a full SYSTEM command prompt window. This results in complete compromise via arbitrary SYSTEM code execution (elevation of privileges).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32232?
CVE-2023-32232 is an issue discovered in Vasion PrinterLogic Client for Windows before version 25.0.0.836, where a standard user can break out of the installer's window running with elevated privileges.
How severe is CVE-2023-32232?
CVE-2023-32232 has a severity rating of 9.9 (Critical).
How does CVE-2023-32232 affect Vasion PrinterLogic Client?
CVE-2023-32232 affects Vasion PrinterLogic Client versions up to and excluding 25.0.0.836 on Windows.
What is the solution for CVE-2023-32232?
To fix CVE-2023-32232, it is recommended to update Vasion PrinterLogic Client to version 25.0.0.836 or later.
Where can I find more information about CVE-2023-32232?
More information about CVE-2023-32232 can be found in the release notes and security bulletin provided by Vasion PrinterLogic.