CVE-2022-32427

PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic Windows Client 25.0.0688 and all affected are advised to upgrade.
Configurations

Configuration 1 (hide)

cpe:2.3:a:printerlogic:windows_client:*:*:*:*:*:*:*:*

History

01 Sep 2022, 04:15

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:printerlogic:windows_client:*:*:*:*:*:*:*:*
Summary PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic Windows Client 25.0.0688 and all affected are advised to upgrade.
References (MISC) https://docs.printercloud.com/1-Printerlogic/Release_Notes/Client_Release_Notes.htm?tocpath=_____9 - (MISC) https://docs.printercloud.com/1-Printerlogic/Release_Notes/Client_Release_Notes.htm?tocpath=_____9 - Release Notes, Vendor Advisory
References (MISC) https://www.printerlogic.com/security-bulletin/ - (MISC) https://www.printerlogic.com/security-bulletin/ - Vendor Advisory

25 Aug 2022, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-25 02:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-32427

Mitre link : CVE-2022-32427

CVE.ORG link : CVE-2022-32427


JSON object : View

Products Affected

printerlogic

  • windows_client
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')