PT-2024-1627 · Microsoft · Printer Metadata Troubleshooter Tool
Stefan Kanthak
·
Published
2024-01-09
·
Updated
2024-05-29
·
CVE-2024-21325
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Printer Metadata Troubleshooter Tool versions prior to the January 5, 2024 update
Description
The issue is related to insufficient input validation in the Microsoft Printer Metadata Troubleshooter Tool, which can allow an attacker to execute arbitrary code. There have been reports of this vulnerability being exploited, with a DLL hijacking vulnerability discovered in the tool. It is estimated that devices that downloaded the tool before January 5, 2024, may be affected.
Recommendations
For versions prior to the January 5, 2024 update, delete the previous version of the Microsoft Printer Metadata Troubleshooter Tool if it was downloaded before January 5, 2024. If the tool was run before the update, no further action is required. As a temporary workaround, consider restricting the use of the tool until the updated version is installed.
Fix
Untrusted Search Path
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Printer Metadata Troubleshooter Tool