Insufficient verification of data authenticity in Printer Driver Packager NX - CVE-2023-30759

 

Insufficient verification of data authenticity in Printer Driver Packager NX - CVE-2023-30759

Published: June 16, 2023


Vulnerability identifier: #VU77474
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30759
CWE-ID: CWE-345
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to the driver installation package fails to detect its modification and may spawn an unexpected process with the administrative privilege. A local user can execute arbitrary program with the administrative privilege.


Affected software

Printer Driver Packager NX

How to mitigate CVE-2023-30759

Install updates from vendor's website.

Printer Driver Packager NX - update to 1.1.26

External References

Related Security Bulletins