#VU25569 Permissions, Privileges, and Access Controls in RICOH COMPANY, LTD. products - CVE-2019-19363
Published: February 25, 2020 / Updated: June 17, 2021
PCL6 Driver for Universal Print
PS Driver for Universal Print
PC FAX Generic Driver
Generic PCL5 Driver
RPCS Driver
PostScript3 Driver
PCL6 (PCL XL) Driver
RPCS Raster Driver
RICOH COMPANY, LTD.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper permissions check. A local user can who can login to the computer where the affected printer driver is installed can use a specially crafted printer driver and gain administrative privileges on the target system.
Remediation
Vendor recommends to download the security program Ver.1.3.0.0.
| Printer Driver | Version | Model Name |
|---|---|---|
| PCL6 Driver for Universal Print | Version 4.0 or later |
|
| PS Driver for Universal Print | Version 4.0 or later |
|
| PC FAX Generic Driver | All versions |
|
| Generic PCL5 Driver | All versions |
|
| RPCS Driver | All versions |
|
| PostScript3 DriverAndPCL6 (PCL XL) Driver | All versions |
Color MFPs
|
| RPCS Raster Driver | All versions |
GELJETs
|