CVE-2023-30759

HIGH

Ricoh Printer Driver Packager NX < 1.1.26 - CSRF

Title source: rule
STIX 2.1

Description

The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may be executed with the administrative privilege.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 18.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-345 CWE-352
Status published
Products (1)
ricoh/printer_driver_packager_nx 1.0.02 - 1.1.26
Published Jun 19, 2023
Tracked Since Feb 18, 2026