PT-2022-17071 · Printix · Printix Secure Cloud Print Management

Logan Latvala

·

Published

2022-03-09

·

Updated

2022-09-03

·

CVE-2022-25090

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Printix Secure Cloud Print Management versions 1.3.1106.0 and earlier
Description The issue is related to the creation of a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation due to a race condition.
Recommendations For versions 1.3.1106.0 and earlier, consider restricting access to the directory where the temp.ini file is created to minimize the risk of exploitation. As a temporary workaround, ensure that the directory permissions are secure to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2022-25090

Affected Products

Printix Secure Cloud Print Management