SB2023061613 - Insufficient verification of data authenticity in Ricoh Printer Driver Packager NX
Published: June 16, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient verification of data authenticity (CVE-ID: CVE-2023-30759)
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to the driver installation package fails to detect its modification and may spawn an unexpected process with the administrative privilege. A local user can execute arbitrary program with the administrative privilege.
Remediation
Install update from vendor's website.