PT-2023-23675 · Vasion · Vasion Printerlogic Client

Published

2023-07-25

·

Updated

2023-12-09

·

CVE-2023-32231

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vasion PrinterLogic Client for Windows versions prior to 25.0.0.818
Description An issue was discovered in the Vasion PrinterLogic Client for Windows. During installation, binaries are executed out of a subfolder in C:WindowsTemp. A standard user can create the folder and path file ahead of time and obtain elevated code execution.
Recommendations For versions prior to 25.0.0.818, update to version 25.0.0.818 or later to resolve the issue. As a temporary workaround, consider restricting access to the C:WindowsTemp folder to prevent standard users from creating malicious folders and files.

Fix

Related Identifiers

CVE-2023-32231

Affected Products

Vasion Printerlogic Client